Built for institutions that answer to a regulator.
Our customers are supervised financial institutions. That shapes every layer of how we build: what data we touch, where it lives, what gets logged, and who can see what.
Single-tenant by architecture
Every institution runs on its own isolated deployment with its own database and its own credentials. There is no shared multi-tenant data store between customers — a boundary that is architectural, not just contractual.
In-country hosting available
For Indonesian institutions, deployments can be hosted on infrastructure physically located in Indonesia, keeping operational data in-country. Hosting location is agreed per engagement and documented in the deployment architecture.
Tamper-evident audit trail
Every message processed, every decision the agent takes, and every administrative action is written to an append-only, tamper-evident audit log — exportable in the shape a compliance reviewer or internal auditor asks for.
Data minimisation by rule
We operate an explicit rule with every institution: sensitive customer data — personal identifiers, account information — does not belong in the channels our agents monitor, and is therefore never fed to an AI model. Retention schedules clean aged data automatically, and a specific individual's data can be fully erased on request.
Encryption in transit
All traffic between users, the platform, and AI services is encrypted in transit over TLS. Administrative consoles carry standard web protections: login brute-force protection, security headers, and CSRF protection on every privileged action.
Permission-scoped access
Answers and reports are scoped to the requester's role and tier — a regional manager sees their region, not the company. Administrative access is role-based and every privileged action is audit-logged.
Human oversight built in
Shadow mode is mandatory before any customer-facing rollout: the agent runs alongside your team and you see exactly what it would have said before any customer hears it. Nothing auto-sends until the institution switches it on, and low-confidence cases escalate to a human.
Consent-gated outreach
Customer outreach honours consent and opt-out automatically, with conduct rules calibrated to the Indonesian regulatory environment — including hard blocks on outreach patterns regulators treat as harassment.
Our products are designed for the regulatory shape our customers operate in: OJK supervisory expectations for Indonesian institutions, Indonesia's personal data protection law (UU PDP), and Singapore's PDPA for our own corporate handling of personal data.
Audit-trail formats, retention behaviour, consent handling, and conduct rules are built to satisfy those frameworks by design — so a compliance review meets a system that was shaped for it, not retrofitted to it.
Our deployment architecture, audit-trail samples, and security documentation are available for review under NDA as part of any procurement conversation.
If you believe you have found a security issue in any Aureus product or site, please write to support@aureusautomation.com and we will respond promptly.
Need the full picture for a procurement review?
We'll walk your IT, security, or compliance team through the deployment architecture and controls for your specific engagement.
Get in touch