Trust Center
Last updated: June 5, 2026
At Aeternum Systems, the security and integrity of the PEIPS platform is a first class requirement, not an afterthought. This Trust Center describes how we protect information, where data lives, the providers we rely on, and the standards we hold ourselves to.
Our Security Principles
- Least privilege: access is granted only where required and reviewed regularly.
- Defense in depth: controls are layered across the network, application, data, and account levels.
- Encryption everywhere: data is encrypted in transit and at rest at all times.
- Tenant isolation: every account is logically isolated and cannot reach another account's data.
- Accountability: every privileged action and every request is logged.
- Continual improvement: controls are reviewed, tested, and improved on a defined schedule.
Security Controls in Place
- Transport encryption using TLS 1.2 or higher on all web traffic.
- Encryption at rest using AES 256 at the database and storage layer.
- Role based access control separating administrative and standard roles.
- Multi factor authentication on every administrative account.
- Row level security on data tables, scoped to the owning account.
- Audit logging of activity with timestamps and request detail.
- Rate limiting and optional IP allowlisting on platform interfaces.
- Automated vulnerability scanning on application code, run on a weekly schedule.
Data Sources and Transparency
PEIPS presents public safety data drawn from publicly available government sources, including state incident based reporting systems and county open data portals. The platform displays this information at the jurisdiction and community level in aggregate form. PEIPS does not introduce personally identifiable information about members of the public beyond what is already published in those sources.
Data Residency
All platform data is hosted on certified cloud infrastructure located in the United States.
Subprocessors
We rely on a small set of trusted infrastructure providers to operate the platform. Each processes data on our behalf under its commercial and security terms.
- Vercel: application hosting and content delivery.
- Supabase: database, authentication, and storage.
- Intelligence processing provider: secured processing of analytical and reporting requests under terms that prohibit the use of customer data to train any model.
We do not sell data, and customer data is never used to train any model.
Data Classification
We classify information into four levels so that handling, access, and retention are applied consistently:
- Public: published materials and documentation.
- Internal: operational notes and non sensitive configuration.
- Confidential: account data and platform content, encrypted and access scoped.
- Restricted: credentials and secrets, held in secure secret stores with access limited to the operator.
Compliance Program
Aeternum Systems maintains a documented information security and governance management system. We are actively building toward formal certification, including ISO 27001 and ISO 42001, with SOC 2 attestation available for clients who require it. The controls described on this page are operational today; formal certification is in progress and not yet complete. We will update this page as milestones are reached.
Incident Response
We maintain a documented incident response process that defines how incidents are detected, escalated, contained, and reviewed, along with a communication plan for affected parties.
Business Continuity and Backups
Platform data is backed up on a regular schedule, and we maintain documented recovery procedures for our core infrastructure dependencies.
Responsible Disclosure
If you believe you have found a security vulnerability, please contact us at cjm@aeternumsystems.com. We review all reports and respond promptly.
Contact
For security or privacy questions, contact Aeternum Systems LLC at cjm@aeternumsystems.com. See also our Privacy Policy and Terms of Service.