AI-assisted business audits · reviewed by humans

Control Summary

Control summary

A high-level, honest view of the security, privacy, and AI-governance controls behind Alpha Scaling — what is implemented today, what is in progress, and what we do not currently claim. This is a posture summary, not an exhaustive control set.

Last updated 25 September 2026

How to read this

Each row states a control area and its current status. We mark a control Implemented only where it is in place in the platform today; where something is not yet in place, or not something we assert, we say so plainly.

Controls

DomainControl areaStatus
Identity & accessAuthenticated access (sessions)Implemented
Identity & accessClient vs staff/auditor role separationImplemented
Identity & accessStaff multi-factor authenticationNot currently claimed
Identity & accessCompromised-password protectionPlanned
Access control & tenancyRow-Level Security, forced with default-denyImplemented
Access control & tenancyOrganization (tenant) isolationImplemented
Access control & tenancyStaff actions via role-checked, logged database functionsImplemented
Data protectionEncryption in transit (TLS)Implemented
Data protectionEncryption at rest (managed by infrastructure providers)Implemented
Data protectionPrivate document storageImplemented
Data protectionSigned-URL-only file accessImplemented
Data protectionData deletion (document soft-delete & organization purge)Implemented
Application securityServer-side privileged operations (not in the browser)Implemented
Application securityServer-side upload validation (deterministic)Implemented
Application securityWebhook signature verification (HMAC-SHA256)Implemented
Application securitySecrets held in environment configuration onlyImplemented
Application securitySecurity response headersImplemented
Application securityContent Security PolicyIn progress (report-only)
AuditabilityAppend-only event log of significant actionsImplemented
AI governanceServer-side, tenant-scoped AI contextImplemented
AI governanceAI data minimization (metadata only; no document contents or financials)Implemented
AI governanceAI prompts and outputs not persisted (audit-metadata event only)Implemented
AI governanceAssistant prevented from producing financial findingsPrevented by design
AI governanceHuman review & publish gate for findingsImplemented
Resilience & operationsBackups / disaster recoveryNot currently claimed
Governance & complianceSOC 2 attestationNot currently claimed
Governance & complianceIndependent (third-party) penetration testNot currently claimed
Governance & compliancePayment-card data handlingNot applicable

This summary is intentionally high-level. It is not the internal control matrix, and it omits implementation detail. For the reasoning behind these controls, see the Security & AI Governance Overview and the Security page.

On certifications

Alpha Scaling designs its security program with relevant SOC 2 Trust Services Criteria in mind. Alpha Scaling does not currently represent itself as holding a SOC 2 attestation unless explicitly stated otherwise.

We hold no SOC 2, ISO 27001, HIPAA, or PCI certification, and there is no “GDPR certification” to hold. Where we describe our program as “SOC 2-aligned,” we mean it is designed with the relevant Trust Services Criteria in mind, not that it has been independently certified. See Trust Center.

Questions about a control

Security & vendor review

Email edward@alpha-scaling.com. Related pages: Security & AI Governance Overview · Security · AI Governance · Subprocessors.