Skip to content

Security and Compliance

Your data. Our responsibility.

Autire holds 401(k), 403(b), and ESOP audit data from payroll providers and recordkeepers. It runs on US-only infrastructure governed by SOC 2 Type 2 controls. Access to the data is provided via your own identity provider.

Compliance and Controls

  • SOC 2 Type 2, audited annually by an independent CPA firm
  • Quarterly third-party penetration testing, with verified remediation
  • Continuous control monitoring via Drata
  • Managed endpoint detection and response (CrowdStrike Falcon Complete), monitored 24/7
AICPA SOC for Service Organizations badge

Security Practices

Data Encryption

AES-256 encryption at rest, TLS 1.2+ in transit, with keys managed in AWS KMS.

AI Governance

Anthropic models on AWS Bedrock, with Guardrails filtering PII and blocking prompt injection. Agent reach is bounded by least-privilege IAM scopes. Audit data never trains a model.

Infrastructure

Hosted on AWS in US regions (us-east-1, us-west-2), AWS WAF, and AWS Shield for DDoS protection.

Audit Trail

AWS CloudTrail and CloudWatch capture environment activity, centralized in CrowdStrike NG-SIEM with 24/7 SOC monitoring.

Vendor Management

Every vendor clears a security review in Drata before onboarding, including SOC 2 report and bridge letter.

Less data. Less exposure.

Autire matches participants by unique identifier, so SSNs are never required to complete an audit. All data resides in US AWS regions, with geo-fencing blocking access from outside the US and each firm's data isolated at multiple levels in both the database and file storage layers. Audit data is retained for seven years to meet audit record requirements. Your data is never sold, never shared for marketing, and never used to train AI models.

FAQ

Is Autire SOC 2 compliant?
Yes. Autire maintains an active SOC 2 Type 2 report on a 12-month cycle, with continuous controls monitoring through Drata between audit windows.
Where is our audit data stored?
In the United States only, hosted on AWS in the US East region (Northern Virginia). Structured data sits in DynamoDB and files in S3, with geo-fencing enabled to reject access from outside the country.
Is our firm's data separated from other firms'?
Yes. Autire is multi-tenant, and each tenant is identified and isolated at multiple levels in both the database and file storage layers.
What authentication methods do you support?
Microsoft SSO through Entra ID over SAML 2.0, with auto-provisioning, or MFA through AWS Cognito using a password plus a one-time passcode. MFA is enforced on all accounts. SSO can be required firm-wide or by role.
How do external reviewers get access without being in our directory?
SSO can be disabled at the role level so peer reviewers, DOL inspectors, and contract auditors authenticate with MFA instead. Their access is scoped to the engagement.
Do you require Social Security numbers?
No. Autire assigns unique identifiers during preprocessing and matches participants across reports using multiple data points, so full SSNs aren't needed.
Does Autire's AI train on our audit data?
No. Client audit data is never used to train or tune any AI model.
How long do you retain our data?
Seven years. Data is never shared with third parties.
How would we hear about a breach?
Within 24 hours, under a formal incident response plan tested annually. Autire has not experienced a cybersecurity incident from inception to date.

Explore More of the Platform

Ready to Transform Your EBP Practice?

Autire gives CPA firms the system to work faster, scale smarter, and deliver better audits.

Autire Technologies, LLC