Skip to main content
Security & Trust Center

Enterprise autonomy requires enterprise trust.

Moving complex data operations from work people manage to work software performs demands clear controls and accountable oversight. Review the verified standards, policies, and governance capabilities behind Autera.

ISO 27001 Certified
SOC 2 Certified
GDPR Rights Addressed

Verified foundations

Trust starts with claims that can be checked. The statements below link directly to Bluemeteor’s public materials.

ISO

ISO 27001:2022

Certified

Bluemeteor announced that it achieved ISO 27001:2022 certification in April 2024, describing the certification as confirmation of its approach to establishing, implementing, maintaining, and continually improving information security management practices.

Review our security foundations
SOC 2

SOC 2

Certified

Bluemeteor is SOC 2 certified. The certification supports enterprise evaluation of the controls Bluemeteor uses to protect customer information and operate its services.

Certification documentation can be provided through the enterprise security-review process.

Granular Platform Controls

True data governance means dictating exactly who—and what—can interact with every single field of your product data. Autera provides precise, configurable guardrails.

Roles & Attribute Access

Configure roles, permissions, approvals, and attribute-level access around enterprise data policies.

Audit History

Use audit history to see what happened, what changed, and how a result was produced.

Validation Guardrails

Apply validation rules, approvals, exceptions, and routing around your organization’s governance requirements.

Confidence Escalation

Allow high-confidence work to proceed and escalate uncertainty for exception handling or human approval.

Responsible AI Governance

Bluemeteor’s AI Terms migration draft preserves existing public provisions while identifying customer-data, provider, security, and technical claims that require current verification.

Customer Data — Migration Review

Existing published AI Terms contain restrictions on how customer data is used and shared. The migration draft preserves that language for verification against current agreements and data-protection documentation.

Third-Party Providers — Migration Review

Existing published AI Terms contain named-provider and contractual-protection language. The migration draft flags current providers and public-disclosure language for verification.

Security Controls — Migration Review

Existing published AI Terms contain encryption, authentication, access-control, and compliance provisions. The migration draft preserves them for technical and legal verification.

Data Handling — Migration Review

Existing published AI Terms contain sanitization, normalization, monitoring, and logging provisions. The migration draft preserves them for technical and legal verification.

Degrees of Autonomy

AI-enabled capabilities may operate within configured rules, permissions, guardrails, confidence thresholds, approvals, and exception policies. Autonomy can reduce routine human involvement while organizations determine appropriate controls for their use cases.

Review the AI Terms draft

Data Privacy & GDPR

Bluemeteor’s Privacy Policy states that it uses technical and organizational measures designed to provide security appropriate to the risk of processing personal data. The policy describes GDPR-related rights and states that Bluemeteor does not sell personal data.

Read our Privacy Policy

Operational Continuity

Bluemeteor’s support organization helps customers resolve issues, understand platform behavior, maintain operational continuity, and adapt Autera as their needs evolve. Specific continuity commitments are handled through the applicable customer agreement.