Trust and compliance

Security
Privacy and compliance
FedRAMP Class C certified
FedRAMP Authorized
Standardized federal security authorization and continuous monitoring for cloud services, ensuring secure handling of U.S. government data.
SOC 1 Type 2
TX-RAMP
Independent audit validating the effectiveness of internal controls over financial reporting across a defined review period.
SOC 2 Type 2
SOC 2 Type 2
Independent audit verifying operational effectiveness of controls for security, availability, confidentiality, and privacy.
ISO 22301:2019
ISO 22301:2019
International standard for business continuity management, ensuring operational resilience during disruptions and crises.
GovRAMP
Gov RAMP
Standardized cloud security and compliance framework designed for state and local government environments.
The General Data Protection Regulation
FedRAMP Authorized
Standardized federal security authorization and continuous monitoring for cloud services, ensuring secure handling of U.S. government data.
TX-RAMP
FedRAMP Authorized
Standardized federal security authorization and continuous monitoring for cloud services, ensuring secure handling of U.S. government data.
Reliability
Reliability is built into every Aurigo deployment. Powered by AWS’s secure, scalable cloud infrastructure, our solutions deliver enterprise-grade resilience and consistent performance. Amazon maintains high security standards for its data centers. Learn more about AWS security. High-availability architecture maximizes uptime, while seamless updates introduce enhancements without disruption. The result is dependable access to mission-critical systems across complex capital programs.


AI transparency
Responsible AI is embedded in Aurigo’s governance framework. Our AI capabilities are designed to support informed human decision-making, with defined oversight and safeguards. Customer environments remain logically separated, and data is never used for model training unless contractually agreed. Our products align with NIST AI RMF v1.0 and ISO 42001 standards.
Business continuity policy
Aurigo maintains a Business Continuity Management System (BCMS) aligned with ISO 22301:2019 to ensure operational resilience and minimal service disruption. The program includes coordinated plans to respond to disruptions and maintain critical operations. Priority is always given to the safety of employees and visitors. The BCMS complies with legal and contractual requirements and is continuously improved through exercises, audits, and lessons learned.

Vulnerability reporting
If you are a security researcher or have identified a potential vulnerability, please review our Vulnerability Disclosure Policy for guidance on responsible reporting. We value coordinated disclosure and appreciate your efforts in helping us strengthen the security, resilience, and integrity of our platform.
Frequently asked questions
How is my data secured and stored?
Aurigo offers built-in security controls and enterprise-grade capabilities that integrate with existing security protocols and compliance standards. Data is protected through preconfigured features, including authentication, authorization, encryption, network security, and data resiliency. Customer environments remain logically separated, and data is never used for model training unless contractually agreed.
What security controls and frameworks does Aurigo follow?
Aurigo aligns with multiple industry-recognized security and compliance frameworks, including FedRAMP, SOC 1 Type 2, SOC 2 Type 2, ISO 22301:2019, GovRAMP, GDPR, and TX-RAMP. The platform also aligns with NIST AI RMF v1.0 and ISO 42001 standards for responsible AI governance.
How do I report a security concern?
If you identify a potential vulnerability, you can report it by following Aurigo’s Vulnerability Disclosure Policy. The company encourages responsible, coordinated disclosure to strengthen platform security, resilience, and integrity.
What is Aurigo's current FedRAMP status?
Aurigo is FedRAMP Authorized, meaning it meets standardized federal security requirements and supports continuous monitoring to ensure secure handling of U.S. government data.
