Sign in →
1 min read

Audit, Security & Compliance

How Aforo secures financial data: an immutable append-only audit trail, role-based access control, SSO/SCIM, and a straight account of where compliance stands (SOC 2 in progress, GDPR processor role, PCI DSS SAQ-A).

Updated 2026-07-29Suggest edits

The Immutable Audit Trail#

Aforo treats every API request as a financial event. Every interaction is logged to a non-repudiable, append-only audit trail.

Request Fingerprinting
Every canAccess check logged with unique Request ID, timestamp, gateway origin, and entitlement logic.
Version History
Every Plan and Margin Guard change is version-controlled. See who changed what and when.
Tamper-Proof Storage
Append-only architecture. Logs cannot be modified or deleted by any user, including administrators.
audit-log-entry.json
{
  "event_id": "audit_7f3a2b1c",
  "timestamp": "2026-03-29T14:32:00.042Z",
  "actor": { "user_id": "user_456", "role": "ADMIN", "ip": "203.0.113.42" },
  "action": "RATE_PLAN_UPDATED",
  "target": { "type": "rate_plan", "id": "rp_uuid_789", "name": "Enterprise AI Tier" },
  "changes": {
    "rate_per_1k_tokens": { "before": 0.003, "after": 0.005 },
    "min_commit": { "before": 500, "after": 1000 }
  },
  "metadata": { "reason": "Provider cost increase — Anthropic pricing update Q2 2026" }
}

Access Control (RBAC)#

Aforo ships six built-in roles. Define custom roles that inherit one of these and narrow it further under Workspace Admin → Roles (see ).

RolePermissionsBest for
ViewerRead-only across dashboards and audit logs; no exports, no PIISupport & Analytics
MemberReads plus community and support participationEveryday operators
DeveloperManage API keys, webhooks, and gateway/integration configEngineering & DevOps
Billing AdminFull billing — invoices, ERP sync, margin guards, reportsFinance & Accounting
AdminEverything except owner-only destructive actionsPlatform operators
OwnerFull access, including user management, SSO, and ownership transferPlatform leads

Global Compliance Standards#

SOC 2 Type II — In Progress
Controls for security, availability, and confidentiality are being implemented ahead of a Type II observation window. No audit has been completed and no report is available yet. Contact your account team for current status.
GDPR & CCPA
Aforo acts as Data Processor. Operator DSR queue (Art. 15-22), an append-only consent ledger (Art. 7), and a breach incident register that tracks the Article 33 72-hour deadline. Contact your account team for the current subprocessor list and DPA.
PCI DSS SAQ-A
Card data is handled entirely by PCI-compliant gateways (Stripe, Razorpay, PayPal, Worldpay) and never touches Aforo infrastructure — the condition SAQ-A exists for. Aforo stores gateway references, never card numbers.

Data Residency#

All Aforo metering and billing data is stored in a single region, AWS us-east-1 (Northern Virginia, United States). Aforo does not currently offer a choice of storage region.

If you are subject to EU or UK data protection law, this means your personal data is transferred to and processed in the United States. Contact your account team for the transfer mechanism that applies to your contract before relying on Aforo for regulated workloads.

US
United States
us-east-1 (Virginia)

SSO Integration#

SECURITY NOTE
Aforo supports SAML 2.0 and OIDC for Single Sign-On, allowing your team to manage access via Okta, Azure AD, or Google Workspace. User provisioning and de-provisioning are automatic via SCIM.