Security and Compliance

Trust controls for teams that need defensible supply chain decisions.

ApertureRisks is built around scoped intake, evidence-labeled output, secure implementation paths, and clear decision-support boundaries. The goal is to help procurement, operations, risk, and compliance leaders understand what the system can prove before sensitive data moves.

Secure intake boundaries

Public forms are designed for inquiry and scoping. Operational files should move through approved intake paths, not public marketing forms.

Evidence-labeled data handling

Outputs distinguish verified, contextual, inferred, unsupported, and missing evidence so a buyer can see what supports each exposure claim.

Controlled ingestion paths

Secure CSV intake is Available today. Automated SFTP is Qualified Enterprise Scope, requiring written technical and security approval. Native API and system connectors are Planned and not yet generally available.

No raw provider leakage

Public buyer surfaces suppress raw provider payloads, stack traces, timeout strings, and internal failure categories.

Append-only agent audit events

Agent draft, approval, rejection, native draft creation, provider outcome, and failure events are stored in append-only ledger tables protected from update and deletion.

Attestation status transparency

SOC 2 has not been completed, and no certification or active audit is claimed. Future independent attestations will be evaluated against customer and contractual requirements.

Procurement readiness

What buyers can review before production rollout.

Enterprise review should not depend on vague trust language. ApertureRisks should provide a clear implementation scope, data categories, ingestion method, access model, retention expectations, and decision-support boundary before client files are exchanged.

Data categories and purpose
Role-based access expectations
Evidence and audit trail handling
Retention and deletion expectations
Approved ingestion method
Current certification and attestation status

Security for AI agents

Cryptographically protected credentials. Human-controlled execution.

Agent preparation does not grant send authority. ApertureRisks requires a recorded human decision and a separately authorized tenant connector before an email draft can be created in the user's mailbox.

AES-256-GCM token sealing

OAuth and Coupa credential payloads are authenticated-encrypted before persistence. Deployment encryption secrets remain outside source control.

Signed, expiring OAuth state

Gmail and Outlook authorization requests bind the provider and tenant scope into a signed state value with a ten-minute expiration.

Fail-closed email draft creation

A connected mailbox cannot create a native draft until an administrator explicitly enables the connector for that provider and tenant. The connector has no send scope.

Provider drafts, not delivery claims

Provider outcomes record the native draft identifier and link. Email delivery is never inferred; the user retains control of sending from Gmail or Outlook.

Control boundary: append-only database enforcement is not described as a cryptographically chained ledger. Formal certifications and independent security attestations have not been completed. Future independent attestations will be evaluated against customer and contractual requirements.

Data Integrity and Professional Accountability

  • ApertureRisks is not a data resale platform. Client data is not sold.
  • Public forms are for inquiry and scoping and should not be used to submit sensitive operational files.
  • Security documentation can be provided to qualified enterprise clients upon request.
  • ApertureRisks is governed through PWLogiConGroup LLC.
  • Operational inquiries route to ian@pwlogicongroup.com.

Security and compliance FAQ

Is ApertureRisks SOC 2 certified?

No. SOC 2 has not been completed, and no certification or active audit is claimed. Future independent attestations will be evaluated against customer and contractual requirements.

Does ApertureRisks share supplier data with third parties?

Supplier and operational records should be used only to support the contracted exposure analysis and platform workflow. Public marketing forms should not collect sensitive operational files.

Can ApertureRisks support GDPR-oriented data handling?

The platform should support scoped collection, purpose limitation, access control, retention discipline, and client-specific data handling terms. Formal legal determinations should be handled by counsel.

How are exposure claims controlled?

Exposure claims are evidence-labeled. The platform separates verified exposure from contextual exposure, inferred signals, unsupported claims, and missing data.