Skip to content

ALORIA TRUST CENTER

Trust is a technical boundary, not a badge wall.

Aloria separates observable public controls, product-specific engineering evidence and external assurance.

CORPORATE WEBSITE BASELINE

Controls configured on the public Aloria site.

These are website controls. Product deployments are evaluated separately.

01

Content Security Policy

Self-origin defaults, blocked object embedding, restricted connect/form destinations and upgrade of insecure requests.

02

Anti-framing controls

frame-ancestors 'none' and X-Frame-Options: DENY.

03

Browser hardening

nosniff, strict-origin referrer handling, explicit permissions restrictions and cross-origin policies.

04

Server-side AI boundary

Provider credentials remain server-side; the Advisor validates origin, payload size and rate limits and uses no-store responses.

AI ADVISOR DATA HANDLING

Know what happens before you type enterprise context.

Initial mapping is taxonomy-based. The final architecture-brief step may use a configured AI model provider; if unavailable, a deterministic fallback is used. Architecture Packs are stored in browser session storage for the current session.

  • Problem input is capped.
  • Origin and payload controls are enforced.
  • Responses are no-store.
  • The current Advisor does not create a server-side Architecture Pack dossier merely for export.

PRODUCT-SPECIFIC TRUST SIGNALS

Engineering evidence stays attached to the product.

Technical diligence verifies the exact control implementation relevant to a proposed deployment.

ARE · FLAGSHIP

Autonomous Revenue Engine

Documented signals include OIDC Authorization Code + PKCE, RS256/JWKS verification, tenant/role claims, HttpOnly SameSite sessions, customer-data AI gates, policy-bound execution, idempotency, append-only audit/evidence, canary controls and a kill switch.

Review ARE →
AGCT · FLAGSHIP

AI Governance Control Tower

AGCT exposes a public interactive demo and technical showcase using representative synthetic data, giving buyers a real interface to inspect before private technical diligence.

Review AGCT →

ASSURANCE BOUNDARIES

What is not implied by default.

External assurance requires independent evidence and, where relevant, written agreement.

NOT IMPLIEDSOC 2 or ISO certification
NOT IMPLIEDRegulatory approval or guaranteed compliance
NOT IMPLIEDFixed data residency across every deployment
NOT IMPLIEDA signed DPA, SLA or security schedule before agreement
NOT IMPLIEDProduction readiness inferred from a demo

Bring your security questions into the product review.