Trust Center

Everything your security, privacy, and audit teams need.

Astridex is built for finance buyers who demand accuracy, auditability, and control. This is where security, privacy, compliance, and AI governance live in one place.

Astridex · Audit trailImmutable logAgentMatched INV-2043 to PO-8809:14autoJ. ChenApproved payment · $21,00009:22approvalAgentFlagged duplicate INV-204409:31exceptionM. OrtizReleased batch of 12 payments10:02approval
Security & trust

Certifications & posture

Status reflects current posture — validate specifics with our team under NDA during procurement.

SOC 2 Type IIAuditedISO 27001CertifiedGDPR compliantCompliantEncryption in transit & at restRole-based access controlImmutable audit loggingSSO / SAMLHIPAA-readyReady

How we protect finance data

The controls that matter to a finance buyer, by design.

Human-in-the-loop

Approval required on every financial action. Agents propose; people approve.

Immutable audit trail

Every action logged with who, what, when, and on what basis — exportable on demand.

Least-privilege access

Granular RBAC and SSO/SAML enforce segregation of duties across systems.

Data residency

Configurable residency and full sub-processor transparency.

Read-only to start

Begin read-only and enable write actions workflow by workflow.

Encryption everywhere

Data encrypted in transit and at rest, with managed key rotation.

Data handling

Astridex processes your finance data under your instructions to perform the workflows you enable. We do not use your data to train shared or third-party models. Access is scoped by role and least privilege, and every access and action is logged.

Retention & deletion

You control retention. Data can be deleted on request, and we provide deletion confirmation. Audit logs are retained per your configured policy to preserve evidentiary integrity.

Sub-processors & residency

We maintain a current list of sub-processors and the purpose of each. Data residency is configurable to meet regional requirements. See the sub-processors page for the current list.

Procurement & security questions

Do you train models on our data?

No. Your data is used only to perform the workflows you enable. We do not use customer data to train shared or third-party models.

What is your compliance status?

SOC 2 Type II is in progress; ISO 27001 and GDPR practices are in place, and we are HIPAA-ready. Current reports and documentation are shared under NDA during procurement.

How do you handle access and segregation of duties?

Role-based access with least privilege, SSO/SAML support, and enforced segregation of duties. Every access and action is logged immutably.

Can we delete our data?

Yes. You control retention and can request deletion, with confirmation provided. Audit logs are retained per your configured policy.

How are incidents handled?

We maintain an incident response process with defined notification timelines, documented in our security package and DPA.

Where is data hosted?

On major cloud infrastructure with configurable residency. The current sub-processor list and locations are published and kept up to date.

Bring agentic finance to your controls team.

We’ll walk security and compliance through the model and share our full documentation package.