How to read this
Each row states a control area and its current status. We mark a control Implemented only where it is in place in the platform today; where something is not yet in place, or not something we assert, we say so plainly.
- Implemented — in place in the platform today.
- Prevented by design — deliberately blocked in the system, not merely discouraged.
- In progress — actively being rolled out.
- Planned — identified and intended, not yet in place.
- Not currently claimed — we do not assert this control at this time.
- Not applicable — does not apply to how the platform works.
Controls
| Domain | Control area | Status |
|---|---|---|
| Identity & access | Authenticated access (sessions) | Implemented |
| Identity & access | Client vs staff/auditor role separation | Implemented |
| Identity & access | Staff multi-factor authentication | Not currently claimed |
| Identity & access | Compromised-password protection | Planned |
| Access control & tenancy | Row-Level Security, forced with default-deny | Implemented |
| Access control & tenancy | Organization (tenant) isolation | Implemented |
| Access control & tenancy | Staff actions via role-checked, logged database functions | Implemented |
| Data protection | Encryption in transit (TLS) | Implemented |
| Data protection | Encryption at rest (managed by infrastructure providers) | Implemented |
| Data protection | Private document storage | Implemented |
| Data protection | Signed-URL-only file access | Implemented |
| Data protection | Data deletion (document soft-delete & organization purge) | Implemented |
| Application security | Server-side privileged operations (not in the browser) | Implemented |
| Application security | Server-side upload validation (deterministic) | Implemented |
| Application security | Webhook signature verification (HMAC-SHA256) | Implemented |
| Application security | Secrets held in environment configuration only | Implemented |
| Application security | Security response headers | Implemented |
| Application security | Content Security Policy | In progress (report-only) |
| Auditability | Append-only event log of significant actions | Implemented |
| AI governance | Server-side, tenant-scoped AI context | Implemented |
| AI governance | AI data minimization (metadata only; no document contents or financials) | Implemented |
| AI governance | AI prompts and outputs not persisted (audit-metadata event only) | Implemented |
| AI governance | Assistant prevented from producing financial findings | Prevented by design |
| AI governance | Human review & publish gate for findings | Implemented |
| Resilience & operations | Backups / disaster recovery | Not currently claimed |
| Governance & compliance | SOC 2 attestation | Not currently claimed |
| Governance & compliance | Independent (third-party) penetration test | Not currently claimed |
| Governance & compliance | Payment-card data handling | Not applicable |
This summary is intentionally high-level. It is not the internal control matrix, and it omits implementation detail. For the reasoning behind these controls, see the Security & AI Governance Overview and the Security page.
On certifications
Alpha Scaling designs its security program with relevant SOC 2 Trust Services Criteria in mind. Alpha Scaling does not currently represent itself as holding a SOC 2 attestation unless explicitly stated otherwise.
We hold no SOC 2, ISO 27001, HIPAA, or PCI certification, and there is no “GDPR certification” to hold. Where we describe our program as “SOC 2-aligned,” we mean it is designed with the relevant Trust Services Criteria in mind, not that it has been independently certified. See Trust Center.
Questions about a control
Security & vendor review
Email edward@alpha-scaling.com. Related pages: Security & AI Governance Overview · Security · AI Governance · Subprocessors.