Security overview
Public entry and continuity controls are documented where the website can prove them.
Infrastructure topology, certifications, audit results and incident metrics are not published without approved records.This page publishes the security position AspireACE can support with its own records. Where a control exists but its public evidence does not, the state says so rather than implying an assurance. Nothing here is a certification claim.
These are the same records the trust centre publishes, narrowed to security. A partial state supports only the written boundary beside it — never an audit, certification or production service level.
Public entry and continuity controls are documented where the website can prove them.
Infrastructure topology, certifications, audit results and incident metrics are not published without approved records.A provider list is not currently approved for public release.
No vendor, hosting location or data-transfer claim is inferred from code or marketing copy.The disclosure workflow is designed but no public security contact is verified.
A security.txt file will not publish a guessed inbox or response promise.No incident SLA or communication channel is claimed without an operational owner.
Service incidents remain an app/operator responsibility until the public policy is approved.This website does not simulate uptime or a live status page.
Availability requires production monitoring evidence, not a decorative green badge.No certification badge appears on the public website.
Certification, audit and compliance claims require scope, issuer, validity and evidence.Listing the absence is part of the control. A reader comparing vendors should be able to see exactly where our published evidence stops.
No public security address is verified yet, so this page does not print one. Until the disclosure record is approved, reach a human through the help centre, which routes to an owned support path rather than an unmonitored mailbox.