Security & trust

Designed for a finance buyer. Controlled by you.

Astridex is built for teams that demand accuracy, auditability, and control. Agents act only under your guardrails.

Astridex · Audit trailImmutable logAgentMatched INV-2043 to PO-8809:14autoJ. ChenApproved payment · $21,00009:22approvalAgentFlagged duplicate INV-204409:31exceptionM. OrtizReleased batch of 12 payments10:02approval
Security & trust

Certifications & controls

Status reflects current posture — validate specifics with our team during procurement.

SOC 2 Type IIAuditedISO 27001CertifiedGDPR compliantCompliantData encryption in transit & at restRole-based access controlFull audit logging

How we keep finance data safe

Human-in-the-loop

Approval required on every financial action. Agents propose; people approve.

Immutable audit trail

Every action logged with who, what, and when — exportable on demand.

Least-privilege access

Granular RBAC enforces segregation of duties across systems.

Data residency

Configurable residency and sub-processor transparency.

Read-only to start

Begin in read-only mode and enable write actions workflow by workflow.

Encryption everywhere

Data encrypted in transit and at rest.

Security FAQ

Do agents take actions without approval?

No. Astridex requires human-in-the-loop approval on every financial action by default. You decide which workflows can act autonomously within guardrails.

What is your compliance status?

SOC 2 Type II is in progress; ISO 27001 and GDPR practices are in place. We share current documentation under NDA during procurement.

How do you handle access?

Role-based access control with least privilege, enforcing segregation of duties. Every access and action is logged.

Bring agentic finance to your controls team.

We’ll walk security and compliance through the model and share documentation.