SECURITY

Security practices and their current scope

Controls visible in the repository and public site are described within their verified boundary.

CURRENT VERIFIED SCOPE

Public Next.js site and repository delivery process

Document last reviewed: August 30, 2026

Reviewed release path

Changes move through a feature branch, automated checks, Vercel Preview and human review before a production decision.

Secrets stay separate

Policy excludes service keys and provider credentials from browser code, documentation, logs and test data.

Public-site headers

The public surface uses content-type protection, frame denial, restricted browser capabilities and Preview search blocking.

Least-privilege direction

Organization data requires an organization boundary and server authorization; cross-organization access is a release blocker.

LIMITS

Current limitations

AIOS does not currently claim SOC 2, ISMS, penetration testing, an uptime SLA, tested recovery objectives or verified tenant isolation across every Production surface.