Security · public edition

Security stated at the boundary we can prove.

This page publishes the security position AspireACE can support with its own records. Where a control exists but its public evidence does not, the state says so rather than implying an assurance. Nothing here is a certification claim.

Control register

Every control carries its own limit.

These are the same records the trust centre publishes, narrowed to security. A partial state supports only the written boundary beside it — never an audit, certification or production service level.

TRUST-02 · PARTIAL

Security overview

Public entry and continuity controls are documented where the website can prove them.

Infrastructure topology, certifications, audit results and incident metrics are not published without approved records.
TRUST-05 · UNAVAILABLE

AI providers and subprocessors

A provider list is not currently approved for public release.

No vendor, hosting location or data-transfer claim is inferred from code or marketing copy.
TRUST-07 · WITHHELD

Vulnerability disclosure

The disclosure workflow is designed but no public security contact is verified.

A security.txt file will not publish a guessed inbox or response promise.
TRUST-08 · UNAVAILABLE

Incident communication

No incident SLA or communication channel is claimed without an operational owner.

Service incidents remain an app/operator responsibility until the public policy is approved.
TRUST-09 · UNAVAILABLE

Service status

This website does not simulate uptime or a live status page.

Availability requires production monitoring evidence, not a decorative green badge.
TRUST-12 · WITHHELD

Certifications and assurance

No certification badge appears on the public website.

Certification, audit and compliance claims require scope, issuer, validity and evidence.
Explicitly not claimed

What this page refuses to say.

Listing the absence is part of the control. A reader comparing vendors should be able to see exactly where our published evidence stops.

No certification or audit badgeCompliance claims require scope, issuer, validity and evidence before they appear anywhere public.
No uptime or incident SLAAvailability and response commitments need production monitoring and a named operational owner.
No published security inboxA disclosure address is printed only once the contact is owned, monitored and verified.
No infrastructure detailTopology, hosting region and subprocessor identity stay withheld until an approved record exists.
Reporting a problem

A real route, not a guessed inbox.

No public security address is verified yet, so this page does not print one. Until the disclosure record is approved, reach a human through the help centre, which routes to an owned support path rather than an unmonitored mailbox.