Security & Control

Financial intelligence should not mean uncontrolled authority.

Auren is being designed around explicit permissions, deterministic policy enforcement, provider boundaries, least-authority progression, and a durable record of financial decisions.

Control Architecture

Intelligence can recommend. Policy decides what is allowed.

Auren separates interpretation from authorization. That boundary is fundamental to how the platform is being designed.

AUTHORITY

Deterministic authorization

Language models may interpret intent and explain recommendations, but permissions, limits, eligibility, signing, and execution controls remain deterministic.

ACCESS

Least authority first

Replay requires no execution authority. Shadow remains read-only. Delegated control expands only through explicit customer policy and authorization.

POLICY

Policy before action

Liquidity floors, approval requirements, account restrictions, timing rules, limits, and permissions are evaluated before an action can become eligible.

PROOF

Execution Proof

Auren is designed to preserve the objective, alternatives considered, rejection reasons, policy checks, authorization, selected action, and realized outcome.

BOUNDARIES

Provider boundaries

Banking, custody, identity, settlement, and regulated financial functions remain with specialized providers where appropriate.

SEPARATION

Interpretation is not authority

Natural-language interpretation can assist users, but it does not confer permission or bypass deterministic controls.

Responsibility Boundaries

Know which system is responsible for what.

Auren should own the intelligence layer while regulated providers continue to perform the functions they are built and licensed to perform.

AUREN

Decision layer

State, intent, policy evaluation, planning, provider abstraction, recommendation logic, proof, and Economic Memory.

PROVIDERS

Regulated infrastructure

Banking, custody, identity, settlement, and other regulated functions remain with specialist providers where appropriate.

CUSTOMER

Delegated authority

The customer defines approvals, permissions, policy, limits, and the scope of authority granted to Auren.

Authority Progression

Earn authority gradually.

The platform begins where execution risk is lowest and increases authority only as the organization chooses to delegate it.

PROOF

Replay

Historical analysis only

No execution authority

OBSERVE

Shadow

Live recommendations

Read-only

APPROVE

Assisted

Prepared execution plans

Human approval required

EXECUTE

Live

Policy-controlled execution

Delegated within limits

DELEGATE

Autopilot

Persistent intent execution

Explicit delegated authority

Diligence Posture

Controls should be specific, testable, and evidenced.

Auren will document its security and control posture as the platform matures, including access control, logging, secrets management, data handling, provider boundaries, incident response, and environment separation. This page intentionally does not claim certifications or controls that have not yet been completed and verified.

Read Auren’s operating principles →