Clarified framework-readiness language and certification boundaries.
AuraOne / Trust / Compliance
Compliance posture, separated from certification claims
AuraOne states framework readiness, safeguards, mappings, and procurement scope without implying an attestation, certification, executed agreement, or customer-specific approval.
Public posture version 1.1 · Public posture reviewed July 11, 2026
Document record
- Version
- Public posture version 1.1
- Effective
- Public posture reviewed July 11, 2026
- Scope
- Public policy and review contact
- Control
- Print, save, copy, and request review
Document summary
What this public document covers
- AuraOne states framework readiness, safeguards, mappings, and procurement scope without implying an attestation, certification, executed agreement, or customer-specific approval.
- Customer-specific architecture, controls, commitments, and contractual terms are confirmed during review and contracting.
How to read this page
A public framework reference identifies a review topic. It does not establish that a certificate, report, agreement, regional configuration, or regulated deployment exists for a specific customer.
Current customer evidence is shared only through the appropriate procurement and security-review process.
Security review materials
AuraOne's public posture does not claim SOC 2 certification or Type II attestation. Security, availability, and confidentiality materials are scoped for buyer review, and any current report is shared through the security review process.
Public status: Controls scoped. Review scope includes relevant security, availability, confidentiality, change, access, incident, and evidence practices.
Sensitive data safeguards
AuraOne's public posture does not claim formal HIPAA compliance. Administrative, technical, and physical safeguards are scoped for sensitive-data workflows, and regulated responsibilities are established during procurement.
Public status: Safeguards scoped. Sensitive health-data scope, responsibilities, safeguards, providers, and contractual requirements are confirmed before such data enters a workflow.
Data processing review
AuraOne's public posture does not claim formal GDPR compliance. Data processing, regional scope, transfer, and request-support responsibilities are established through buyer review and executed program documents.
Public status: DPA scoped. Controller and processor roles, lawful basis, regional scope, transfers, subprocessors, retention, and request support depend on the program.
ISO 27001 control mapping only
AuraOne's public posture includes ISO 27001 as a control-mapping and buyer-review topic. AuraOne does not claim ISO 27001 certification; certification status, certificate, scope, and dates would be established by current verified evidence.
Public status: Certification not claimed. A control mapping is not a certification claim.
Customer review and contracting
The review begins with the product, deployment, source data, users, providers, jurisdictions, and decision the customer needs to operate. AuraOne then scopes relevant architecture, controls, privacy, legal, and evidence materials.
Change history
Published the initial compliance posture and procurement review process.
Compliance review
Define the review scope
The review distinguishes public posture from customer-specific evidence and executed terms.
- Framework
- Named requirement, role, jurisdiction, and dateCustomer review brief
- System
- Product, deployment, providers, data, and usersArchitecture scope
- Evidence
- Relevant policies, controls, tests, and recordsCurrent review materials
- Outcome
- Open questions, accepted scope, and governing termsProcurement decision record