Service status ·A8 Core™ · The Operating System for Financial Accounts ·The account operating system · API-first
Trust center

Security you can audit.

A8 Core™ is built to the control expectations of regulated financial infrastructure, secured by B5 Secure™. This is where we publish how we protect your data — what is live today, what is in progress, and the evidence behind every claim.

Compliance posture

We label every framework by where it actually stands. We do not claim a certification we do not yet hold.

SOC 2 Type IIIn progress

Examination of security, availability, and confidentiality controls.

ISO 27001Targeted

Information-security management system aligned to ISO 27001.

PCI DSSTargeted

Cardholder-data flows scoped to PCI DSS where they apply.

GDPR / CCPAAvailable

Data-protection rights honored for EU and California residents.

A8 Core™ is pre-launch. The controls described on this page are operational today; formal certifications are on our roadmap. Current attestations, assessment summaries, and our certification timeline are shared under NDA.

How we protect your data

The same controls that make A8 Core™ suitable for regulated institutions are available for your review.

Encryption everywhere

TLS 1.3 in transit (TLS 1.2 minimum), AES-256 at rest. Signing keys are isolated in an HSM-backed store.

Least-privilege access

SSO, MFA, and role-based access across all internal systems, with full audit logging.

Continuous monitoring

Continuous detection and vulnerability scanning, with independent penetration testing planned. See data protection for what is operating today and what is not.

Evidentiary records

Every directive is logged with a RequestId, producing an immutable, audit-ready trail.

Tenant isolation

Provider credentials scope every request, so there is no cross-provider data access.

Resilience

Multi-AZ redundancy, automated backups, and a tested business-continuity plan.

Authorization for humans — and their agents

Most platforms authorize a request. A8 Core™ authorizes the actor and the action.

Data-element-level

Entitlements are evaluated on every call, down to individual data elements — not cached or inferred at the edge. Access to a record never implies access to every field on it.

Dual-principal: user + agent

When an autonomous agent acts for a user, both the user’s entitlement and the agent’s are evaluated together, so an agent can never exceed the human it acts for. This is enforced by B5 Secure™’s Adaptive Data Authorization.

Inside B5 Secure™

Five layers, applied to every request. This is how B5 Secure™ makes “Never Trust” operational for .NET 10.

B1

Identity & session integrity

FIDO2, passkeys, and continuous session validation establish who is acting before anything else runs.

B2

Signed requests

Inbound API calls authenticate with HMAC-SHA256 in the Authorization header (HMAC keyId:signature:timestamp), with an RFC 9421 HTTP Message Signatures profile available for 2026. Webhook deliveries carry an RFC 9421 HTTP Message Signature, verified with HMAC-SHA256 or, for third-party endpoints, Ed25519 — so a partner checks A8 Core™’s deliveries against a published public key with no shared secret to leak. Signatures prove integrity and authenticity — they do not encrypt — so traffic always travels over TLS as well. See webhook verification.

B3

Adaptive Data Authorization

Data-element-level entitlements for both users and agents, evaluated per request rather than assumed from a role.

B4

Evidentiary records

Every decision and directive is written to an immutable, audit-ready trail keyed by RequestId.

B5

Continuous assurance

Monitoring, anomaly detection, key rotation, and a post-quantum path (ML-KEM, ML-DSA) keep the fabric current as threats evolve.

Layer scope shown for orientation; exact boundaries are detailed in the security package.

Powered by B5 Secure™

The security pipeline behind A8 Core™

A8 Core™’s security is built and operated as B5 Secure™ — a zero-trust “Never Trust” architecture for .NET 10. Same controls, audited independently, surfaced through one platform.

Explore B5 Secure™

Request our security package

Current control attestations, our certification roadmap, subprocessor list, and DPA are available under NDA — with assessment summaries as they are completed. Start with our mutual NDA.

Contact security
Build with confidence

Infrastructure you can audit.

See how A8 Core™ secures every account, action, and agent — and the evidence behind each control.

Scroll to Top