Comprehensive security and compliance information for Aster Agents platform
Authentication & Access Control
Code Security Practices
Framework | Status | Notes |
---|---|---|
SOC 2 Type II | In Progress | Independent audit underway, expected Q4 2025 |
GDPR | Compliant | DPA & SCCs available on request |
HIPAA | Not Covered | PHI should not be stored in Aster Agents |
Continuous Monitoring
Patch Management
Bug Bounty Program
Vendor | Purpose | Trust Center / SOC 2 |
---|---|---|
Vercel | Front-end hosting & Node.js serverless functions | Security |
Modal | Python serverless execution backend | Security Guide |
Neon (PostgreSQL) | Serverless Postgres database hosting (part of Databricks) | Security |
Cloudflare R2 | File storage & CDN | Trust Hub |
Clerk | Authentication & RBAC | Security Overview |