[ TRUST ]
Private by construction.
Not as an afterthought.
Built for companies that take security seriously, from the ground up, not retrofitted before an audit. And where a certification is in progress rather than complete, we say so.
[ THE STANDARD ]
Every part of Actaa
clears the same five tests.
- 01
Private by construction
All AI runs through AWS Bedrock inside our own AWS account, with no model training, ever, and nothing sent to a consumer AI service. Your data stays inside the enterprise security boundary.
- 02
Isolated by architecture
Every company's data is architecturally separated. No shared context, no cross-tenant leakage, no blended results, enforced below the application, not just in the UI.
- 03
Compliant by design
Every flow mapped to its regulation before it ships: GDPR erasure and portability, SOC 2 controls, and AEDT employment law: the hiring AI produces no score, rank or recommendation on a person.
- 04
Secured from day one
AES-256 at rest, TLS 1.2+ in transit, TOTP MFA, and AWS WAF with managed rule groups at the edge. Sensitive actions write an append-only audit record with actor, IP and timestamp. No SSH, no bastion hosts: all operations run through AWS Systems Manager.
- 05
Priced to replace the stack
One subscription instead of ten. One bill, one security review, one login, for the whole company, not per tool.
[ SECURITY & COMPLIANCE ]
Enterprise security.
An honest posture.
Where a certification is in progress rather than complete, we say so. No badge we haven't earned.
GDPR IMPLEMENTED
Article 17 (erasure) and Article 20 (portability) implemented. Available to any user with an Actaa Network profile from their Network settings, and to anyone else on request to your workspace admin. Export your profile, documents, files inventory, mailbox inventory and audit history as JSON; mail exports as a standard mbox archive. Erasure anonymizes your identity across every workspace and cannot be undone. Deleted workspaces, mailboxes and mail keep a 30-day restore window.
SOC 2 ALIGNED
Architected to SOC 2 controls: multi-region CloudTrail with log-file validation, consent tracking with policy versioning, append-only audit records on sensitive actions, and encryption and access control mapped to the standard. Not yet certified.
ISO 27001 SUPPORTED
Supported via the compliance infrastructure layer, encryption, access control and audit posture mapped to the standard. Not yet certified.
AEDT ALIGNED
Not an automated employment decision tool. The hiring AI extracts and summarizes what a candidate wrote; it never scores, ranks, filters or recommends a person, and five independent layers enforce that. Designed with NYC LL 144, California FEHA, Illinois HB 3773 and the Colorado AI Act in view.
Out of scope, on purpose
HIPAA is not supported. The platform is not configured for Protected Health Information and no Business Associate Agreement is offered, so PHI must not be uploaded. We would rather tell you that here than after you have signed.
Encryption
Data is encrypted at rest with AES-256: S3 objects with SSE-S3, sensitive database fields with AES-256-GCM, and secrets in AWS Secrets Manager. TLS 1.2+ in transit. Encryption uses AWS-managed keys.
Access
AWS Cognito with advanced security, TOTP MFA, 6 roles and 10+ granular permissions. Department-scoped access.
Infrastructure
The database runs inside our VPC and is not reachable from the internet. S3 locked down, VPC-isolated, AWS WAF at the edge. Operations run through AWS Systems Manager only: no SSH, no bastion host.
[ AUDIT EVERYTHING ]