SECURITY

Security as the floor, not the feature.

Our audience can’t take chances with their data, so we didn’t design as if they could. The strongest security posture is the one where your most sensitive work barely leaves your control in the first place.

Less of your data in the cloud to begin with.

Aleora runs client-side, in your browser. For much of what you do, your data never has to be sent anywhere. Where others work hard to prove their cloud is safe enough to hold your numbers, we changed the question: there’s far less to hold.

Never trained on your data

Not by us, and, by contract, not by the model you choose.

Bring your own model. No lock-in.

Use the model your firm approves; switch as the market moves.

Host it yourself

Deploy to your own infrastructure where you need to, though client-side execution means many won’t have to.

Encryption, in transit and at rest

To the standard financial institutions hold, specifics in the security documentation.

Access control

SSO via SAML/OIDC, passwordless by default, role-based permissions enforced server-side, MFA.

Certifications

ISO 27001, GDPR, SOC 2, what’s in place and what’s in progress, stated honestly.

Data residency, sub-processors, retention, incident response, penetration testing, answered in full in our security documentation.

The detail your reviewer will ask for.