Content Security Policy
Self-origin defaults, blocked object embedding, restricted connect/form destinations and upgrade of insecure requests.
ALORIA TRUST CENTER
Aloria separates observable public controls, product-specific engineering evidence and external assurance.
CORPORATE WEBSITE BASELINE
These are website controls. Product deployments are evaluated separately.
Self-origin defaults, blocked object embedding, restricted connect/form destinations and upgrade of insecure requests.
frame-ancestors 'none' and X-Frame-Options: DENY.
nosniff, strict-origin referrer handling, explicit permissions restrictions and cross-origin policies.
Provider credentials remain server-side; the Advisor validates origin, payload size and rate limits and uses no-store responses.
AI ADVISOR DATA HANDLING
Initial mapping is taxonomy-based. The final architecture-brief step may use a configured AI model provider; if unavailable, a deterministic fallback is used. Architecture Packs are stored in browser session storage for the current session.
PRODUCT-SPECIFIC TRUST SIGNALS
Technical diligence verifies the exact control implementation relevant to a proposed deployment.
Documented signals include OIDC Authorization Code + PKCE, RS256/JWKS verification, tenant/role claims, HttpOnly SameSite sessions, customer-data AI gates, policy-bound execution, idempotency, append-only audit/evidence, canary controls and a kill switch.
Review ARE →AGCT exposes a public interactive demo and technical showcase using representative synthetic data, giving buyers a real interface to inspect before private technical diligence.
Review AGCT →ASSURANCE BOUNDARIES
External assurance requires independent evidence and, where relevant, written agreement.