PartnersTrust CenterInvestorsCareers

01TRUST CENTER

Security is the architecture,
not an appendix.

Most vendors secure their products once a year, in the weeks before an audit. CAELION builds the controls into the architecture, so the secure state is the default state: read-only access unless policy grants more, data that stays inside your boundary, credentials that exist only as long as the task, and evidence written as work happens. This page describes how — plainly, in the terms your security team will ask about.

READ-ONLY / IN-BOUNDARY / LEAST-PRIVILEGE / EVIDENCEControls by construction · not attestation season

02THE CUSTOMER BOUNDARY

Your environment stays your environment.

Zero-ingestion architecture: Cube23, Trace8, and Meridian reason over your telemetry, configuration, and identity data in place — in-account, against live APIs and stores — rather than replicating it into a vendor warehouse. There is no CAELION-side copy of your environment to breach, subpoena, or misplace, and data-residency questions answer themselves: the data never moved.

  • Read-only by default
  • Data stays in boundary
  • Least-privilege IAM
  • JIT execution
  • No standing credentials
  • Customer policy
  • Reversible actions
  • Evidence as work happens

Customer boundary

AWS AccountsIdentity StoresLogs & TelemetrySIEMConfigurationControl Planes

CAELION platforms

Deploy in-account and reason over data where it already lives. Analysis goes to the data — the data does not travel to the analysis. Access is scoped, just-in-time, and expires with the task; every touch lands in the audit trail.

03ARCHITECTURE PRINCIPLES

Four decisions that do most of the work.

These are not policies we ask people to follow. They are properties of how Cube23, Trace8, and Meridian are built — which means they hold on the worst day, not just the audited one.

01

Read-only by default

Our products deploy with inspection rights, not action rights. They observe, correlate, and recommend before they are ever permitted to change anything — and write capability, where introduced, is scoped by explicit policy after read-only operation has built the evidence base for it. The blast radius of a misbehaving component is bounded by construction.

02

Data stays in your boundary

Zero-ingestion architecture: our platforms reason over your telemetry, configuration, and identity data in place — in-account, against live APIs and stores — rather than replicating it into a vendor warehouse. There is no CAELION-side copy of your environment to breach, subpoena, or misplace, and data-residency questions answer themselves: the data never moved.

03

Least-privilege IAM and just-in-time execution

Access is scoped to the minimum each function requires, and elevated permissions are granted just-in-time for a specific task, then expire. No standing write access, no shared long-lived credentials, no role that quietly accumulates scope. What an agent or engineer can do is defined before the work starts — and stops being possible when it ends.

04

Evidence and audit trails as work happens

Every query, finding, and action is written to an audit trail at the moment it occurs, with the underlying evidence attached. Audit preparation stops being an archaeology project: the record your assessors want is the same record our platforms produce as a side effect of operating. Nothing is reconstructed after the fact, because nothing needs to be.

04FRAMEWORK ALIGNMENT

Built against the frameworks your assessors use.

We engineer against the major frameworks rather than retrofitting to them — which is why the same architecture answers cleanly across regulators and sectors. Formal attestations are shared with customers under NDA as programs complete.

Aligned to the frameworks your auditors ask about

NIST CSFNIST CSF
ISO 27001ISO 27001
SOC 2SOC 2
GDPRGDPR
HIPAAHIPAA-READY
Aligned to NIST CSF · ISO 27001 · SOC 2 · GDPR · HIPAA-ready deployment patterns · DORA · PCI-DSS
ALIGNMENT DETAIL · PER FRAMEWORKENGINEERED, NOT RETROFITTED
NIST CSFThe platform architecture is aligned to the Identify–Protect–Detect–Respond–Recover functions: continuous asset and posture visibility, least-privilege controls, evidence-backed detection and investigation, and auditable, reversible response.
ISO 27001Our engineering and operations practices are designed for ISO 27001’s control families — access control, cryptography, operations security, supplier relationships — with control ownership and evidence generation built into how pods work day to day.
SOC 2Products and managed services are engineered against the Trust Services Criteria — security, availability, and confidentiality — with the continuous audit trail providing the evidence stream a SOC 2 examination expects.
GDPRThe zero-ingestion model is designed for GDPR’s data-minimization and residency expectations: personal data is processed inside the customer’s boundary, under the customer’s controls, with no vendor-side replication to complicate the processing record.
HIPAADeployment patterns are engineered against HIPAA’s requirements by keeping PHI in place: our platforms reason over data inside the covered entity’s environment, so PHI never transits to or rests in CAELION infrastructure.
DORA & PCI-DSSFor financial-services and payments engagements, deployments are aligned to DORA’s operational-resilience expectations and designed for PCI-DSS scoping — in-boundary processing, segmented access, and continuous evidence for third-party risk and audit requirements.

05DATA HANDLING & ACCESS MODEL

The questions security teams ask first.

Q·01

What data do your products store?

As little as the work requires. Under the zero-ingestion model, Cube23, Trace8, and Meridian reason over your data where it already lives — your logs, your telemetry, your configuration and identity stores — rather than copying it into a vendor warehouse. What the platforms retain is operational metadata: findings, case files, audit records, and the configuration of the deployment itself. Raw environment data stays in your environment.

Q·02

Where does processing happen?

Inside your boundary. Meridian runs in your AWS account on Amazon Bedrock AgentCore and reasons over your live AWS APIs; Trace8 and Cube23 deploy in-account against your existing stores and control planes. Analysis goes to where the data is — the data does not travel to the analysis. This is also why residency and sovereignty questions tend to resolve quickly in review: the processing location is your location.

Q·03

Who can access customer environments?

Named individuals, with scoped access, for defined work. Pod engineers operate under least-privilege roles specific to their engagement; elevated access is granted just-in-time for a task and expires with it; and every access and action is written to the audit trail as it happens. There is no anonymous, standing, firm-wide access to customer environments — you can enumerate who could touch your systems, and see what they did.

Q·04

How are agent actions controlled?

Structurally, in layers. Agents start read-only, with no standing write access. What they can touch is bounded by tool allow-lists and least-privilege IAM before any reasoning happens; what they may do is bounded by explicit policy scoping that you define. Write actions, where enabled, are auditable and reversible, and conclusions carry their evidence so a human can verify before — or after — anything changes. Autonomy is expanded deliberately, domain by domain, as the evidence base earns it.

06RESPONSIBLE DISCLOSURE

If you find something, we want to hear it.

We take good-faith security research seriously and treat reporters as collaborators, not adversaries. Security researchers can reach us via the address published in /.well-known/security.txt, which also carries our disclosure policy and scope.

  • Reports acknowledged promptly, by a human on the security team
  • Good-faith research conducted within the published scope will not be met with legal action
  • We keep reporters informed through triage, remediation, and disclosure
  • Credit given where the reporter wants it — and discretion where they don’t

Ask us the hard questions.

Bring your security architects and your assessors’ checklist. We’ll walk the architecture end to end — boundaries, credentials, audit trails — with the engineers who built it, and share attestation detail under NDA.

Read-only by default · Data stays in your boundary · Evidence generated as work happens