[ TRUST ]
Private by construction.
Not as an afterthought.
Built for companies that take security seriously, from the ground up, not retrofitted before an audit. And where a certification is in progress rather than complete, we say so.
[ THE STANDARD ]
Every part of Actaa clears the same five tests.
- 01
Private by construction
All AI runs through AWS Bedrock, no model training, ever, and no third-party endpoints. Your data stays inside the enterprise security boundary.
- 02
Isolated by architecture
Every company's data is architecturally separated. No shared context, no cross-tenant leakage, no blended results, enforced below the application, not just in the UI.
- 03
Compliant by design
Every flow mapped to its regulation before it ships: GDPR erasure and portability, SOC 2 controls, and AEDT employment law.
- 04
Secured from day one
AES-256 at rest, TLS 1.2+ in transit, TOTP MFA, WAF protection and immutable audit trails on every action. No open ports, no bastion hosts.
- 05
Priced to replace the stack
One subscription instead of ten. One bill, one security review, one login, for the whole company, not per tool.
[ SECURITY & COMPLIANCE ]
Enterprise security.
An honest posture.
Where a certification is in progress rather than complete, we say so. No badge we haven't earned.
GDPR IMPLEMENTED
Article 17 (erasure) and Article 20 (portability) implemented. One-click export, anonymized deletion with a 30-day recovery window.
SOC 2 ALIGNED
Architected to SOC 2 controls, CloudTrail audit logging, consent tracking with policy versioning, full action trails. Not yet certified.
AEDT ALIGNED
A 5-layer defense against AI making employment decisions. Aligned with NYC LL 144, California FEHA, Illinois HB 3773 and the Colorado AI Act.
ISO 27001 SUPPORTED
Supported via the compliance infrastructure layer, encryption, access control and audit posture mapped to the standard. Not yet certified.
HIPAA NOT SUPPORTED
The platform is not configured for Protected Health Information, and no Business Associate Agreement is offered. PHI must not be uploaded.
Encryption
AES-256 at rest on every database, file and secret. TLS 1.2+ in transit. Secrets in AWS Secrets Manager with rotation.
Access
AWS Cognito with advanced security, TOTP MFA, 6 roles and 10+ granular permissions. Department-scoped access.
Infrastructure
Private-subnet RDS with no public access, S3 locked down, VPC-isolated, WAF-protected. Operations via SSM only, no open ports.
[ AUDIT EVERYTHING ]