Security

Security Built for Government

This page is written for the people who have to say yes: CIOs, CISOs, IT directors, and the attorneys who advise them. It explains how Aric protects government data in every portal and assistant we operate.

Our Commitments

Four principles behind every decision

Your data stays yours

Your government owns its data, always. We return or destroy it on request at the end of an engagement, and we never use it to train AI models.

Least privilege everywhere

Every account, service, and integration gets the minimum access it needs, for the shortest time it needs it. No shared accounts, ever.

Nothing without authorization

We touch your systems only with written authorization that names who approved it, what is in scope, and when. Verification is read-only.

Evidence over assertions

We are an assessment company. We hold ourselves to the standard we assess others against, and we will show you, not just tell you.

Identity and access control

Sign-in to our portals is built on Microsoft Entra ID, the same identity platform most governments already run, with support for multi-factor authentication and your existing conditional-access policies. Inside the portal, role-based access control decides what each person can see and do: a department lead sees their department's work, an executive sees reporting, and administrative functions are held to named, individual accounts. Each customer's environment is logically separated from every other customer's, and access ends when your engagement does or the moment you ask.

Encryption and data protection

All traffic between your users and our portals is encrypted in transit with TLS. Data at rest, including databases and uploaded evidence files, is encrypted on Microsoft Azure's government-grade infrastructure in United States regions. Evidence files such as contracts, configurations, and screenshots are stored in dedicated encrypted storage separate from the application, and are retrievable only through the portal's access controls. Backups are automatic, encrypted, and tested.

How we handle your credentials

Some engagements involve your government providing credentials so we can verify how systems connect. Those credentials are stored only in a managed secrets vault, never in code, documents, spreadsheets, or email. They are used solely for the purpose you authorized, by the checks you authorized, and they are revoked or returned the moment they are no longer required. This commitment is written into our contracts, not just our marketing.

Verification is read-only and authorized in writing

When an engagement includes live connection checks against your systems, the rules are strict: a named City official authorizes each system in writing, checks run only in agreed windows, they are read-only, and every check and its result is logged. For systems that cannot be reached from outside your network, verification runs through a relay your own staff install and control on your premises, so nothing opens your network to the internet. We never scan, probe, or touch anything outside the authorized list.

Audit trails and accountability

Every consequential action in our portals is recorded: who signed in, what they viewed or changed, what evidence was added, and what checks were run, with timestamps. Audit records cannot be edited from within the application. This is what lets a CIO answer an auditor, an open-records request, or a council question with a record instead of a recollection, and it applies to Aric's own staff exactly as it applies to yours.

Infrastructure and operations

Our portals run on Microsoft Azure's managed platform services in U.S. regions, which means operating-system patching, physical security, and platform hardening are handled by Microsoft's compliance-certified infrastructure, and Aric's effort goes into the application layer. Production is separated from development, changes are reviewed and tested before they ship, database schema changes are applied through controlled migrations rather than by hand, and the platform is monitored around the clock. Where your requirements call for it, deployments can run inside your government's own Azure subscription or entirely on your premises.

Secure development practices

Security is part of how the software is written, not a review at the end. Code changes are reviewed before release, automated test suites run against every build, dependencies are kept current, and service identities follow the same least-privilege rule as human accounts. Secrets never live in source code. Administrative and machine interfaces require their own authentication and are never exposed as conveniences.

AI-specific safeguards

Our Resident Assistant and Staff Assistant follow additional rules because AI in front of the public deserves extra caution. Assistants answer only from content your government approves, with guardrails that keep them on topic. They perform lookups or transactions against your systems only where you have explicitly authorized each capability, and those actions are logged like any other. Conversations are monitored for quality and abuse, questions the assistant should not answer are handed to your staff, and we are contractually explicit that a language-model assistant can be wrong, which is why guardrails, testing, and human oversight are part of every deployment rather than optional extras. Your data is never used to train the underlying models.

Frameworks and obligations we work within

Our assessment methodology is built around recognized frameworks including the NIST Cybersecurity Framework and CIS Controls, and we apply the same lens to our own systems. We design our handling of your information around the obligations governments actually carry: open-records laws, records-retention schedules, and the heightened care due for data connected to public safety and utility systems. Security terms, breach notification, and liability are addressed plainly in our contracts, where your attorney can evaluate them.

Ask us the hard questions

A page like this is where diligence starts, not where it ends. We are glad to sit down with your IT staff and walk through our architecture, our data handling, and our contracts in as much depth as you need, under NDA where appropriate. If your evaluation process includes a security questionnaire, send it. We answer those for a living.

Questions CIOs Ask Us

Answers before you have to ask

Where exactly does our data live?

In Microsoft Azure data centers in the United States, encrypted in transit and at rest. If your policies require more control, portal and assistant deployments can run inside your government's own Azure subscription or entirely on your premises. The platforms that hold your data are named in your agreement; we do not pass it to anyone else.

Who at Aric can see our data?

Only the people working your engagement, each under an individual named account with the least privilege their role needs. Their access is captured in the same audit trail as your own users' activity, and it ends when the engagement does.

Is our data used to train AI models?

No. Your assessment data, evidence, documents, and assistant conversations are used to serve your government and for nothing else. Assistants read your approved content to answer questions; nothing you give us trains the underlying models.

What happens if you have a breach?

You hear from us promptly, you get our cooperation fully, and those obligations are written into the contract along with liability terms that treat data breaches more strictly than ordinary claims. We would rather explain our incident response before you sign than after something happens.

Can your connection checks break our systems?

The checks are read-only by design: they confirm that a documented endpoint answers and returns what the documentation says, and nothing more. They run only against systems a named official authorized in writing, only in agreed windows, and every check is logged. We never scan, probe, or explore beyond the authorized list.

Do we have to open our network to you?

No. Systems that are not reachable from the internet stay that way. Verification for those systems runs through a small relay that your own staff install and control on your premises; nothing inbound is opened, and your team can shut it off at any time.

Can our staff sign in with our own accounts and MFA?

Yes. Sign-in is built on Microsoft Entra ID, so your users can authenticate with the accounts, multi-factor authentication, and conditional-access policies your IT department already manages. Deprovision someone on your side and their portal access ends with it.

How do you support open-records requests and retention schedules?

Everything in the portal is your government's data, so it is available to you for records requests, and the audit trail shows who touched what and when. We configure retention and disposition around your schedules rather than imposing our own, and your attorney sets the policy; our job is making it possible to follow.

What happens to our data if we leave?

You take it with you. At the end of an engagement we return your data in usable formats and, on request, destroy our copies and confirm it in writing. Your reports, evidence, and records are deliverables you own, not hostages to a renewal.

Request a security briefing

Bring your CIO, your IT staff, and your toughest questions. We will bring the details.

Talk to Aric