Security Overview

Last updated: 3 September 2026

Contracting entity: Ariesnet, Inc.

Written for a buyer’s security review. Where a line says “on request”, email legal@aramai.net.

Credential-free import. CoreModels imports the artifacts your tools already produce (for example dbt manifests, JSON Schema files, OpenAPI documents). It does not need your warehouse, database, or API credentials to build a model.

Isolation. Each customer’s projects are logically isolated. Enterprise plans can be deployed on dedicated infrastructure or in your private cloud.

Encryption. Data in transit is encrypted using TLS 1.2 or higher. All customer data is encrypted at rest using industry-standard encryption. Encryption keys are managed and rotated following best practices.

Access control. Role-based access on all plans (builder / view-only). Enterprise adds SSO/SAML, IP allow-listing, and audit logs.

Agents and the MCP endpoint. Agents authenticate with the same credentials as people and inherit the same project permissions. Each principal is limited to 15 concurrent in-flight requests; Enterprise throughput is set in contract.

Backups and retention. daily backups, retention period, restore test cadence.

Certifications. We do not currently hold SOC 2 or ISO 27001 certification. These are on our roadmap.

Vulnerability reporting. security@aramai.net We acknowledge within 2 business days.

Subprocessors and hosting region. See the Data Processing Addendum.

Questions: legal@aramai.net