How Aforo secures financial data: an immutable append-only audit trail, role-based access control, SSO/SCIM, and a straight account of where compliance stands (SOC 2 in progress, GDPR processor role, PCI DSS SAQ-A).
Controls for security, availability, and confidentiality are being implemented ahead of a Type II observation window. No audit has been completed and no report is available yet. Contact your account team for current status.
GDPR & CCPA
Aforo acts as Data Processor. Operator DSR queue (Art. 15-22), an append-only consent ledger (Art. 7), and a breach incident register that tracks the Article 33 72-hour deadline. Contact your account team for the current subprocessor list and DPA.
PCI DSS SAQ-A
Card data is handled entirely by PCI-compliant gateways (Stripe, Razorpay, PayPal, Worldpay) and never touches Aforo infrastructure — the condition SAQ-A exists for. Aforo stores gateway references, never card numbers.
All Aforo metering and billing data is stored in a single region, AWS us-east-1 (Northern Virginia, United States). Aforo does not currently offer a choice of storage region.
If you are subject to EU or UK data protection law, this means your personal data is transferred to and processed in the United States. Contact your account team for the transfer mechanism that applies to your contract before relying on Aforo for regulated workloads.
Aforo supports SAML 2.0 and OIDC for Single Sign-On, allowing your team to manage access via Okta, Azure AD, or Google Workspace. User provisioning and de-provisioning are automatic via SCIM.