# Auctum Security and Compliance Whitepaper (SE)

Version: 1.0  
Date: 2026-05-15

## Purpose

This whitepaper summarizes how Auctum designs, operates, and audits security for Swedish bookkeeping and compliance workloads.

Source documents used:
- ISMS_INFORMATION_SECURITY_POLICY.md
- ISMS_COMPLIANCE_AUDIT.md
- GDPR_COMPLIANCE_REVIEW.md
- ARCHITECTURE.md
- DATABASE.md

## 1. Executive Summary

Auctum is a multi-tenant SaaS platform for accounting and business operations. Security is built into architecture and process controls.

Core commitments:
- Confidentiality: strict authorization boundaries and tenant isolation
- Integrity: immutable and traceable accounting events
- Availability: production-grade backups and disaster recovery controls
- Compliance: Swedish bookkeeping and GDPR-aligned processing
- Continuous improvement: recurring audits and remediation plans

## 2. Regulatory Scope (Sweden)

Auctum is designed for organizations operating under Swedish requirements, including:
- Bokforingslagen (BFL)
- Mervardesskattelagen (ML)
- GDPR and related data protection obligations

Platform implementation supports:
- Long-term accounting data retention
- Verifiable traceability for financial records
- Controlled correction workflows instead of destructive edits
- Export capability for accounting and audit workflows

## 3. Information Security Management

The ISMS is aligned to ISO/IEC 27001:2022 principles and documents:
- Information Security Policy with roles and responsibilities
- Cryptographic baseline and key handling expectations
- Incident response process and escalation responsibilities
- Supplier and third-party control model
- Annual review cycle with targeted remediation tracking

Recent internal compliance audit highlights:
- Critical findings were remediated in extension permissions, cryptography, and privacy safeguards
- Remaining items are focused on process maturity and formal documentation completeness

## 4. Technical Security Architecture

### 4.1 Identity and Access

- Authentication is provided by Supabase Auth and integrated identity flows where applicable
- Access control relies on row-level security and tenant-scoped policies
- Least privilege is applied for users, services, and integrations

### 4.2 Data Protection

- Encryption in transit with TLS
- Encryption at rest for sensitive data classes
- Data minimization principles for regulated and immutable contexts
- Prohibition against storing secrets in source code

### 4.3 Integrity and Auditability

- Financial record changes are auditable
- Posted accounting entries are not overwritten; corrections are additive
- Tamper-evident patterns are used where immutability is required

### 4.4 Backup and Recovery

- Encrypted backups
- Point-in-time recovery support
- Operational controls for restoration and continuity

## 5. Privacy and GDPR

Auctum implements GDPR-aligned controls, including:
- Purpose limitation and data minimization
- Legal basis mapping for accounting-related processing
- Data subject request handling workflows
- Retention and deletion controls with legal retention carve-outs

## 6. Vendor and Supply Chain Controls

Key service providers are evaluated with security and privacy controls in scope.

Typical control areas include:
- Data processing agreements
- Scoped API permissions
- Logging and auditability
- Contractual and operational review points

## 7. Incident Management

Auctum uses a structured response model:
- Triage and containment
- Impact assessment and remediation
- Communication plan for affected stakeholders
- Post-incident review and control hardening

## 8. Customer-Facing Security Practices

Organizations can use platform capabilities for stronger control posture, including:
- Access governance and role enforcement
- Security and compliance settings in administrative workflows
- Audit evidence export paths

## 9. Limitations and Shared Responsibility

Security is a shared model. Auctum secures the platform and managed services; each customer is responsible for:
- Internal access governance
- Endpoint security and credential hygiene
- Correct process operation in their organization

## 10. Contact

For security questions, architecture clarifications, or compliance documentation requests, use the public contact form at:

https://auctum.se/contact?topic=security
