Security

An engineering responsibility

Care designed into the system.

Security is part of how AonHive frames, builds, and operates software—not a review deferred until the end.

Our baseline

Reduce exposure. Make decisions visible. Prepare for failure.

Controls should follow the actual system, data, and operating risk. We prefer clear boundaries and proportionate safeguards over security theatre.

Working practices

Security stays connected to delivery.

  1. 01

    Secure by design

    Threats, trust boundaries, failure modes, and sensitive paths are considered while the system is still being shaped.

  2. 02

    Minimize access and data

    Systems should collect only what the outcome requires and grant people and services the narrowest practical access.

  3. 03

    Control change

    Dependencies, code changes, environments, and releases need reviewable paths and quality gates proportionate to their risk.

  4. 04

    Prepare for production

    Observability, recovery, ownership, and incident learning are treated as product capabilities.

  5. 05

    Keep AI accountable

    Applied AI work includes evaluation, data boundaries, human oversight, and explicit behavior when confidence is insufficient.

Responsible disclosure

Report a potential issue directly.

If you believe you have found a security issue affecting this website or an AonHive-managed system, send a concise report with the affected surface, reproduction steps, and potential impact. Please avoid accessing data that is not yours or disrupting availability while investigating.