Trust Center
How AAND protects your data and enforces compliance — written plainly for the procurement, IT, and security teams who evaluate us. We mark what’s live today, what’s in progress, and what’s on the roadmap. We never claim a certification we don’t hold.
Security & infrastructure
Authentication & role-based access
Every user is authenticated; access is scoped by role (client, vendor, inspector, admin) and re-checked on the server for every action.
Encryption in transit (TLS/HTTPS)
All traffic is served over HTTPS.
Multi-tenant data isolation
Each organization sees only its own records; ownership is verified server-side on every read and write. A formal third-party isolation test is in progress.
Secrets management
Credentials live in environment configuration, never in source code, and are never exposed to the browser.
Managed, compliant hosting
Hosted on Vercel and Supabase infrastructure (themselves SOC 2 audited).
Security response headers
Enforced on every response: HSTS (forced HTTPS), X-Frame-Options (anti-clickjacking), X-Content-Type-Options (no MIME-sniffing), and Referrer-Policy.
Single sign-on (SAML) & SCIM provisioning
Authentication runs on Clerk, which supports enterprise SSO and SCIM provisioning. The app is SSO-ready; activation is a per-customer configuration step (Okta, Microsoft Entra, Google).
Compliance & certifications
SOC 2 Type II
The control framework data centers and hospitals expect. A formal readiness tracker maps every Trust Services control to its current state; core technical controls (access control, encryption + HSTS, audit logging, input validation) are already in place.
ISO 27001
Information-security management certification — planned alongside SOC 2.
GovRAMP / StateRAMP (state & local government)
Authorization for public-sector buyers — Phase 2.
FedRAMP (federal civilian)
Federal cloud authorization — Phase 3, with an agency sponsor.
CMMC L2 / DFARS / ITAR (defense & controlled data)
A separate controlled-data enclave for defense work — Phase 4.
Data handling & privacy
In-app account & data deletion
Users can delete their account and data from Settings at any time.
Data export
Your records (findings, jobs) export to CSV on demand.
Privacy policy & terms
Published and linked in-app.
Data residency (US) for government work
US-only data residency and personnel controls for controlled/defense data — Phase 3+.
Vendor risk & compliance enforcement
Insurance (COI) verification & expiry tracking
Certificates of insurance are tracked with expiration alerts; expired insurance blocks dispatch automatically.
Pre-qualification gate
Only vendors who hold the service-type capability, cover the site, carry valid insurance, and are in good compliance standing can be dispatched or bid on a job.
Verified-credential dispatch gate
Vendor trade credentials are verified against issuing authorities, and held credentials give a dispatch edge today. Hard-blocking dispatch on a missing verified credential is rolling out in monitoring mode first, so it never blocks a job on a credential we can't yet confirm.
AAND-Verified standard
A portable, continuously-monitored qualification record; buyers can require AAND-Verified vendors.
Audit trail & activity log
Actions are logged; every facility gets a one-tap audit binder for inspectors and insurers.
SLA management
Response and arrival SLAs are tracked with at-risk and breach flags.
Enterprise readiness
Multi-site / portfolio reporting
Executive and operations dashboards roll up across all facilities.
ERP / accounting integration
Bi-directional invoice and PO sync with buyer financial systems — Phase 2.
Accessibility (WCAG)
Working toward WCAG 2.1 AA conformance.
Security & procurement questions
For security questionnaires, a current status letter, or a compliance review, contact admin@aandnetwork.com.
AAND Compliance Platform · This page reflects our current posture and is updated as items advance.