Enterprise Grade Compliance & MFA
Mandatory MFA for enterprise users, TOTP step-up on destructive actions, and the SHA-256 hash-chain audit log behind them — the controls our SOC 2 Type II audit examines.
We have shipped mandatory MFA for all enterprise-tier accounts and a new SHA-256 hash-chain audit log that provides cryptographic evidence of every privileged action taken on your tenant. These are the controls a SOC 2 audit examines, and our SOC 2 Type II certification is in progress.
Where we are on SOC 2 Type II
SOC 2 Type II is an independent audit performed over a continuous observation period, which verifies that security, availability and confidentiality controls work as described. We are in that process; the report has not been issued yet and we do not claim to hold one. For current status, or to discuss what your procurement needs and when, write to security@auralius.ai.
Mandatory MFA for Enterprise
Enterprise accounts now require TOTP-based multi-factor authentication for all users. To enroll, navigate to Settings → Security → Enable MFA, scan the QR code with your authenticator app, and confirm with a 6-digit code. Existing sessions are invalidated immediately after enrollment.
TOTP step-up for destructive actions
Any action tagged HIGH or CRITICAL — such as erasing tenant data, rotating API keys, or approving a financial action — now requires a fresh TOTP confirmation even during an active session. This step-up is enforced server-side and cannot be bypassed by a stolen session cookie.
Hash-chain audit log
Every privileged action writes a record to an append-only SHA-256 hash chain stored in Postgres. Each record includes the actor, timestamp, payload, and the hash of the previous record — making the chain tamper-evident without the cost of external KMS hardware signing. You can verify the chain integrity at any time via GET /mcp/audit/verify.
What is next
We are working toward GDPR Data Processing Agreement templates for EU tenants and HIPAA-ready configuration for healthcare use cases. Follow this blog for updates.
Published August 5, 2026 · Kolerr Lab