Trust center · updated 2026-07-29

Controls a buyer can verify before enforcement.

Security architecture

Every stateful query is scoped to an organization. Sessions, API keys, and SCIM tokens are one-way hashed. Published policies, authorization decisions, approval outcomes, and organization audit events retain their operational history.

Enterprise identity

The inherited factory supports OIDC Authorization Code flow with PKCE, signed identity-token validation, domain restriction, encrypted client secrets, and SCIM user provisioning.

Integrations and billing

Stripe webhooks are signature-verified and replay-protected. Managed OAuth brokers provider authorization so Adranum stores workspace-scoped connection identifiers rather than raw provider credentials.

Infrastructure

The deployment supports a non-root container behind TLS with a read-only filesystem, dropped capabilities, health checks, resource limits, and encrypted off-box backup support.

Procurement documents

Data processing addendum · Security architecture · Privacy notice · Service terms

Assurance status

Adranum does not claim SOC 2, ISO 27001, official SAP certification, or another assurance without current independent evidence.