Security & Shared Responsibility
Foundation One is built for Trust & Corporate Services Providers (TCSPs) who manage other people's wealth, structures and obligations. This page sets out our security posture honestly: what we hold, what we are working toward, and exactly where the responsibility line sits between Foundation One and your firm.
Assurance status — stated plainly
We do not claim certifications we do not hold. Where a framework is listed as control-mapped, we implement the full control set but have not yet completed independent third-party attestation. Where it is listed as compliant, we are built to meet the framework's requirements.
| Framework | Status | What this means |
|---|---|---|
| SOC 2 Type II | Control-mapped | Full Trust Services Criteria controls implemented. Independent Type II attestation in progress. Controls matrix available under Mutual NDA. |
| ISO 27001 | Control-mapped | Annex A control set implemented and operated. Certification audit scheduled. Statement of Applicability available under Mutual NDA. |
| GDPR | Compliant | Act as data processor under Article 28 terms. DPA available. EU & UK representative appointed. |
| FATCA / CRS / AEOI | Compliant | Reporting workflows built in for US FATCA, OECD CRS and jurisdiction-specific AEOI schemas. |
| EU AI Act | Ready | AI Risk Register, human-in-the-loop governance and model documentation aligned to the AI Act's transparency and risk-management obligations. |
| AML / KYC | Compliant | Beneficial-ownership tracking, KYC refresh cycles and sanctions screening integrations supported. |
The complete controls matrix (mapping each SOC 2 Trust Services Criterion and ISO 27001 Annex A control to its implementation) and our latest penetration-test report are available to qualified prospects under Mutual NDA. Request a Mutual NDA →
How we protect your data
Encryption
- AES-256 encryption at rest for all databases, object storage and backups.
- TLS 1.3 for all data in transit, with HSTS enforced.
- Customer-managed encryption keys (CMEK) available on Enterprise for sensitive vaults.
Access control
- Role-based permissions down to the field level, with time-boxed delegation and break-glass.
- SSO / SAML & SCIM provisioning on Growth and above.
- All staff access is least-privilege, MFA-enforced and fully audited.
Monitoring & resilience
- Anomalous access and transactions flagged in real time, with SOC triage.
- Multi-region active-active deployment with 99.99% uptime SLA target.
- Nightly verified backups with point-in-time recovery and regular restore drills.
- External penetration testing at least annually; critical findings remediated within agreed SLAs.
Data sovereignty
- We never train AI models on your clients' data. Ever.
- Full data export, anytime — your data stays yours.
- Data residency options available (EU, UK, Mauritius, US) on Enterprise.
Shared responsibility matrix
Security for a TCSP platform is a shared effort. The table below defines which party is responsible for each control area. F1 = Foundation One (Aphelion Ltd). Customer = your firm.
| Control area | Foundation One | Customer | Notes |
|---|---|---|---|
| Platform infrastructure security | Responsible | — | Hosted infrastructure, OS, database and application hardening. |
| Encryption at rest & in transit | Responsible | — | AES-256 & TLS 1.3 enabled by default. CMEK optional on Enterprise. |
| Application-level access control | Responsible (tooling) | Responsible (configuration) | F1 provides RBAC, roles & permissions. Customer assigns roles & reviews access. |
| User provisioning & de-provisioning | — | Responsible | Customer manages who has access via SSO/SCIM or manual admin. |
| Identity provider (SSO/SAML) | Responsible (integration) | Responsible (IdP operation) | Customer operates their IdP; F1 integrates with standard SAML/OIDC providers. |
| Data classification & handling rules | — | Responsible | Customer defines what data is stored and how it is classified. |
| Audit log integrity & retention | Responsible | — | Immutable, tamper-evident audit trail captured automatically. |
| Audit log review & alert response | Responsible (platform alerts) | Responsible (business response) | F1 flags anomalies; customer investigates & acts on business-level events. |
| Backup & disaster recovery | Responsible | — | Nightly verified backups, multi-region DR, point-in-time recovery. |
| Penetration testing (platform) | Responsible | — | Annual independent pen-test; report under NDA. |
| Regulatory reporting (FATCA/CRS/AEOI) | Responsible (workflows) | Responsible (filing) | F1 generates the reports; customer reviews & files with authorities. |
| KYC / AML screening | Responsible (integrations) | Responsible (decisions) | F1 integrates screening providers; customer owns KYC decisions & risk rating. |
| Customer data export & deletion | Responsible (tooling) | Responsible (requests) | Customer initiates export/deletion; F1 fulfils within agreed SLAs. |
| Security awareness training | — | Responsible | Customer trains their staff on firm-specific security policies. |
Vulnerability disclosure & reporting
We welcome responsible disclosure of security vulnerabilities. If you believe you have identified a security issue, please email security@apheliontrust.com with details. We acknowledge receipt within one business day and provide a remediation timeline after triage. Please do not publicly disclose a vulnerability before we have had the opportunity to remediate it.
Requesting the controls matrix or pen-test report
The full SOC 2 / ISO 27001 controls matrix and the latest penetration-test summary are shared with qualified prospects and customers under Mutual NDA. To request access:
- Sign and return our Mutual NDA.
- Email security@apheliontrust.com with your firm name and the engagement context.
- We provide the documentation within two business days of NDA execution.
Questions about this page or our security posture? Contact our team →