Encryption Standards
All financial ledgers, working papers, and user identifying data are encrypted in transit and at rest.
- Data at Rest: Encrypted using military-grade AES-256 block-level encryption. Database backups are distributed across multiple availability zones and identically encrypted.
- Data in Transit: All communications between the client browser, our Node.js/Python microservices, and external endpoints use TLS 1.3 cryptography.
- Key Management: Encryption keys are rotated automatically every 30 days via a managed Hardware Security Module (HSM).
Cloud Infrastructure & Resilience
AuditAI is hosted on enterprise-grade cloud infrastructure, designed for high availability and strict data isolation to ensure zero cross-contamination of client ledgers.
- Multi-AZ Redundancy: Our application and database instances are distributed across multiple Availability Zones. In the event of a localized data center failure, traffic automatically fails over with zero downtime.
- Database Isolation (PostgreSQL): We utilize Row-Level Security (RLS) and logical separation at the database level. Each audit engagement and SME workspace operates within strict bounds to prevent unauthorized cross-tenant data access.
- DDoS & WAF Protection: Edge networks equipped with Web Application Firewalls (WAF) inspect all incoming traffic, automatically mitigating DDoS attacks and SQL injection attempts before they reach our microservices.
NRS API Security (NTAA 2025)
To comply with the Nigeria Tax Administration Act (NTAA) 2025, our transmission pipeline to the Nigeria Revenue Service (NRS) utilizes a zero-trust architecture.
Mutual TLS (mTLS)
Tax filings are not transmitted via standard API keys. Both our servers and the NRS servers cryptographically verify each other's certificates before any CIT or VAT data is exchanged.
Payload Hashing
Every tax computation payload is signed with a SHA-256 hash. This guarantees non-repudiation, ensuring the filed data cannot be tampered with in transit.
Access & Authorization
Because we handle statutory audits and tax filings, our authorization matrix goes beyond standard SaaS permissions. We explicitly enforce International Standards on Auditing (ISA) guidelines.
Maker / Checker Enforcements
Under ISA 230, Junior Auditors (Makers) can draft working papers and clear AI anomalies, but they cannot lock an engagement. Only a designated Audit Partner (Checker) can apply the final digital sign-off.
Session Integrity & MFA
Multi-Factor Authentication (MFA) is strictly enforced for Auditor and SME Owner accounts. Idle sessions are automatically terminated after 15 minutes of inactivity to prevent unauthorized physical terminal access.