# Aembit security posture

> How Aembit approaches, implements, and maintains security

Using Aembit for workload credentials extends your security boundary. This section provides transparency into how Aembit protects your data, meets compliance requirements, and defends against threats.

![SOC 2 Type II certified](/3p-logos/soc-2-type-2-logo.png)![ISO 27001 certified](/3p-logos/iso-27001-logo.png)

> **Core security principles**
>
> * **Defense in depth**: Multiple layers of security controls, not single points of failure
> * **Least privilege**: Components and services only have access they need
> * **Zero trust**: Aembit verifies every request, regardless of source
> * **Transparency**: Aembit documents security practices and makes them auditable
>
> For more information about compliance, monitoring, and subprocessors, see the [Aembit Trust Center](https://app.drata.com/trust/9cc6b899-0c38-11ee-865f-029d78a187d9).

![](/aembit-icons/gears-light.svg)

[Security architecture](/get-started/security-posture/architecture)Component isolation, data protection, encryption in transit and at rest, and secure communication patterns.

→

![](/aembit-icons/shield-check-light.svg)

[Security compliance](/get-started/security-posture/security-compliance)SOC 2 Type II certification, ISO 27001 compliance, and data protection requirements.

→

![](/aembit-icons/shield-halved-light.svg)

[Threat model](/get-started/security-posture/threat-model)Attack vectors, trust boundaries, and the controls that mitigate risks in Aembit deployments.

→

![](/aembit-icons/magnifying-glass-light.svg)

[Metadata collection](/get-started/security-posture/metadata-collection)The minimal metadata Aembit collects to operate the platform, and the analytics this documentation site collects.

→