SECURITY BY ARCHITECTURE

Intelligent systems must also be responsible systems.

AJ Partners incorporates security, access control, data protection and human oversight from the initial design of every system.

We design security architectures aligned with ISO/IEC 27001:2022 principles and the Trust Services Criteria used in SOC 2 examinations. Controls, responsibilities and regulatory requirements are defined for each implementation.

SHARED RESPONSIBILITY MODEL

Security is a shared responsibility

Each part of the system has specific responsibilities. AJ Partners designs the architecture, the client makes business decisions, and technology providers maintain the infrastructure.

AJ Partners

Design and implementation responsibilities

  • Architecture design
  • Access-control design
  • Workflow boundaries
  • AI-role limitations
  • Integration configuration
  • Logging architecture
  • Implementation testing
  • Human-approval design

Client organization

Business responsibilities

  • Data-source authorization
  • User-access approval
  • Internal security policies
  • Legal basis for processing
  • Industry-specific obligations
  • Employee access management
  • Final human decisions

Technology providers

Infrastructure provider responsibilities

  • Infrastructure controls
  • Provider availability
  • Provider encryption capabilities
  • Provider incident-response obligations
  • Provider certifications

Provider certifications do not automatically transfer to AJ Partners or to client systems.

CORE CONTROLS

Controls included in the security design

Identity and access management

  • Role-based access
  • Least privilege
  • Administrator separation
  • Authentication controls

Data protection

  • Encryption in transit
  • Encryption at rest where supported
  • Secure secrets handling
  • Data minimization

Application security

  • Server-side validation
  • Input sanitization
  • Dependency management
  • OWASP-oriented testing

Auditability

  • Event logging
  • Administrative activity records
  • Workflow histories
  • Incident investigation support

AI governance

  • Human approval thresholds
  • Restricted actions
  • Knowledge boundaries
  • Escalation paths
  • Output monitoring

Business continuity

  • Backup strategy
  • Restore testing
  • Recovery planning
  • Failure handling
  • Vendor dependency review

These controls are confirmed during the client architecture process.

STANDARDS ALIGNMENT

Designed to support environments with more demanding requirements

SOC 2

Controls can be mapped to relevant security, availability, confidentiality, processing integrity and privacy criteria, depending on client scope.

ISO/IEC 27001:2022

The architecture can be designed to support the information security management system and the organization’s risk assessment process.

Industry-specific requirements

Additional requirements are identified during discovery, including data protection, retention, audit, data residency and human approval.

No HIPAA, PCI DSS, GDPR or other compliance is claimed unless the specific implementation has been assessed.

ARCHITECTURE PROCESS

How we design security

Phase 1

Data and system discovery

We identify what information exists, where it resides and which systems process it.

Phase 2

Risk and dependency review

We assess risks, vendor dependencies and regulatory requirements.

Phase 3

Access and integration design

We define roles, permissions, integration boundaries and approval rules.

Phase 4

Security validation and testing

We validate controls, input testing and output rules before launch.

Phase 5

Monitoring and continuous improvement

We establish logging, monitoring and continuous improvement processes.

HONEST DISCLOSURE

The use of technology providers with security certifications does not automatically transfer those certifications to AJ Partners or to client systems. Compliance scope must be evaluated and documented for each organization.

Read: Security for Enterprise AI Systems