Security you can audit.
A8 Core™ is built to the control expectations of regulated financial infrastructure, secured by B5 Secure™. This is where we publish how we protect your data — what is live today, what is in progress, and the evidence behind every claim.
Compliance posture
We label every framework by where it actually stands. We do not claim a certification we do not yet hold.
Examination of security, availability, and confidentiality controls.
Information-security management system aligned to ISO 27001.
Cardholder-data flows scoped to PCI DSS where they apply.
Data-protection rights honored for EU and California residents.
A8 Core™ is pre-launch. The controls described on this page are operational today; formal certifications are on our roadmap. Current attestations, assessment summaries, and our certification timeline are shared under NDA.
How we protect your data
The same controls that make A8 Core™ suitable for regulated institutions are available for your review.
Encryption everywhere
TLS 1.3 in transit (TLS 1.2 minimum), AES-256 at rest. Signing keys are isolated in an HSM-backed store.
Least-privilege access
SSO, MFA, and role-based access across all internal systems, with full audit logging.
Continuous monitoring
Continuous detection and vulnerability scanning, with independent penetration testing planned. See data protection for what is operating today and what is not.
Evidentiary records
Every directive is logged with a RequestId, producing an immutable, audit-ready trail.
Tenant isolation
Provider credentials scope every request, so there is no cross-provider data access.
Resilience
Multi-AZ redundancy, automated backups, and a tested business-continuity plan.
Authorization for humans — and their agents
Most platforms authorize a request. A8 Core™ authorizes the actor and the action.
Data-element-level
Entitlements are evaluated on every call, down to individual data elements — not cached or inferred at the edge. Access to a record never implies access to every field on it.
Dual-principal: user + agent
When an autonomous agent acts for a user, both the user’s entitlement and the agent’s are evaluated together, so an agent can never exceed the human it acts for. This is enforced by B5 Secure™’s Adaptive Data Authorization.
Inside B5 Secure™
Five layers, applied to every request. This is how B5 Secure™ makes “Never Trust” operational for .NET 10.
Identity & session integrity
FIDO2, passkeys, and continuous session validation establish who is acting before anything else runs.
Signed requests
Inbound API calls authenticate with HMAC-SHA256 in the Authorization header (HMAC keyId:signature:timestamp), with an RFC 9421 HTTP Message Signatures profile available for 2026. Webhook deliveries carry an RFC 9421 HTTP Message Signature, verified with HMAC-SHA256 or, for third-party endpoints, Ed25519 — so a partner checks A8 Core™’s deliveries against a published public key with no shared secret to leak. Signatures prove integrity and authenticity — they do not encrypt — so traffic always travels over TLS as well. See webhook verification.
Adaptive Data Authorization
Data-element-level entitlements for both users and agents, evaluated per request rather than assumed from a role.
Evidentiary records
Every decision and directive is written to an immutable, audit-ready trail keyed by RequestId.
Continuous assurance
Monitoring, anomaly detection, key rotation, and a post-quantum path (ML-KEM, ML-DSA) keep the fabric current as threats evolve.
Layer scope shown for orientation; exact boundaries are detailed in the security package.
The security pipeline behind A8 Core™
A8 Core™’s security is built and operated as B5 Secure™ — a zero-trust “Never Trust” architecture for .NET 10. Same controls, audited independently, surfaced through one platform.
Request our security package
Current control attestations, our certification roadmap, subprocessor list, and DPA are available under NDA — with assessment summaries as they are completed. Start with our mutual NDA.
Infrastructure you can audit.
See how A8 Core™ secures every account, action, and agent — and the evidence behind each control.