SECURITY BY ARCHITECTURE
Intelligent systems must also be responsible systems.
AJ Partners incorporates security, access control, data protection and human oversight from the initial design of every system.
We design security architectures aligned with ISO/IEC 27001:2022 principles and the Trust Services Criteria used in SOC 2 examinations. Controls, responsibilities and regulatory requirements are defined for each implementation.
SHARED RESPONSIBILITY MODEL
Security is a shared responsibility
Each part of the system has specific responsibilities. AJ Partners designs the architecture, the client makes business decisions, and technology providers maintain the infrastructure.
AJ Partners
Design and implementation responsibilities
- Architecture design
- Access-control design
- Workflow boundaries
- AI-role limitations
- Integration configuration
- Logging architecture
- Implementation testing
- Human-approval design
Client organization
Business responsibilities
- Data-source authorization
- User-access approval
- Internal security policies
- Legal basis for processing
- Industry-specific obligations
- Employee access management
- Final human decisions
Technology providers
Infrastructure provider responsibilities
- Infrastructure controls
- Provider availability
- Provider encryption capabilities
- Provider incident-response obligations
- Provider certifications
Provider certifications do not automatically transfer to AJ Partners or to client systems.
CORE CONTROLS
Controls included in the security design
Identity and access management
- Role-based access
- Least privilege
- Administrator separation
- Authentication controls
Data protection
- Encryption in transit
- Encryption at rest where supported
- Secure secrets handling
- Data minimization
Application security
- Server-side validation
- Input sanitization
- Dependency management
- OWASP-oriented testing
Auditability
- Event logging
- Administrative activity records
- Workflow histories
- Incident investigation support
AI governance
- Human approval thresholds
- Restricted actions
- Knowledge boundaries
- Escalation paths
- Output monitoring
Business continuity
- Backup strategy
- Restore testing
- Recovery planning
- Failure handling
- Vendor dependency review
These controls are confirmed during the client architecture process.
STANDARDS ALIGNMENT
Designed to support environments with more demanding requirements
SOC 2
Controls can be mapped to relevant security, availability, confidentiality, processing integrity and privacy criteria, depending on client scope.
ISO/IEC 27001:2022
The architecture can be designed to support the information security management system and the organization’s risk assessment process.
Industry-specific requirements
Additional requirements are identified during discovery, including data protection, retention, audit, data residency and human approval.
No HIPAA, PCI DSS, GDPR or other compliance is claimed unless the specific implementation has been assessed.
ARCHITECTURE PROCESS
How we design security
Phase 1
Data and system discovery
We identify what information exists, where it resides and which systems process it.
Phase 2
Risk and dependency review
We assess risks, vendor dependencies and regulatory requirements.
Phase 3
Access and integration design
We define roles, permissions, integration boundaries and approval rules.
Phase 4
Security validation and testing
We validate controls, input testing and output rules before launch.
Phase 5
Monitoring and continuous improvement
We establish logging, monitoring and continuous improvement processes.
HONEST DISCLOSURE
The use of technology providers with security certifications does not automatically transfer those certifications to AJ Partners or to client systems. Compliance scope must be evaluated and documented for each organization.
Read: Security for Enterprise AI Systems