Trust center · updated 2026-07-29
Controls a buyer can verify before enforcement.
Security architecture
Every stateful query is scoped to an organization. Sessions, API keys, and SCIM tokens are one-way hashed. Published policies, authorization decisions, approval outcomes, and organization audit events retain their operational history.
Enterprise identity
The inherited factory supports OIDC Authorization Code flow with PKCE, signed identity-token validation, domain restriction, encrypted client secrets, and SCIM user provisioning.
Integrations and billing
Stripe webhooks are signature-verified and replay-protected. Managed OAuth brokers provider authorization so Adranum stores workspace-scoped connection identifiers rather than raw provider credentials.
Infrastructure
The deployment supports a non-root container behind TLS with a read-only filesystem, dropped capabilities, health checks, resource limits, and encrypted off-box backup support.
Procurement documents
Data processing addendum · Security architecture · Privacy notice · Service terms
Assurance status
Adranum does not claim SOC 2, ISO 27001, official SAP certification, or another assurance without current independent evidence.