AI-assisted business audits ยท reviewed by humans

Data Governance

Data Governance

The operational and technical companion to our Privacy Policy: how data moves through Alpha Scaling from collection to deletion, who can reach it, and the controls that keep each client’s data separate.

Last updated 25 September 2026

How this relates to the Privacy Policy

Our Privacy Policy is the plain-language statement of what we collect and the choices you have. This page is the operational and technical detail behind it: the data lifecycle, the access model, and our vendor flows. Where this page says “audit,” it means an operational and financial profit diagnostic — not a statutory or GAAP financial-statement audit or attestation.

On this page

Data classification

We handle several kinds of data at different sensitivity levels. The most sensitive material is business data our clients entrust to us; the least sensitive is marketing data captured on our funnel pages, which is kept apart from the application.

Business-sensitive

Operational & financial data

Engagement metadata, checklist responses, automated check verdicts and findings. Treated as confidential and scoped to the owning organization.

Most sensitive

Uploaded documents

Business and financial documents a client uploads. Held in private storage, processed server-side, and never sent to the AI assistant.

Lower sensitivity

Account & marketing data

Account and profile details for portal access, and — separately — funnel lead data captured on marketing pages, kept apart from the application.

What data we hold

This map shows each category of data, where it lives, whether AI processes it, and whether a person reviews it.

CategoryWhere it livesAI processed?Human reviewed?Notes
Account / profile
name, email, role, org
Profiles + Supabase AuthOrganization name onlyStaff manage—
Organization infoOrganizationsName only to assistantYes—
Engagement metadata
status, dates, day target
EngagementsYes (status / timeline)Yes—
Audit intake / checklistChecklist itemsLabels + status to assistantYesThe questionnaire.
Uploaded documents
business / financial
Documents + private StorageContents not sent; engine processes server-sideValidated + staff reviewSensitive.
Document check verdictsDocument checksVerdict label to assistantYesDeterministic checks.
Audit findings
leak zones, ranges, confidence
FindingsEngine-produced, zone-agent scoredPublish gate + audit-team estimateOnly source of client-facing numbers.
Deliverables / reportsDeliverables (private bucket)NoPublished by staff—
MessagesMessages—Staff / client—
Activity eventsEvents (append-only)——Auditability.
Funnel lead data
name, email, phone, company, revenue bracket, trucks
Typeform → webhook → Meta (hashed)No—Marketing only, separate from the app.

Data lifecycle

Business data follows the same path from the moment it is submitted to the moment it is removed.

  1. 1CollectionYou submit account details, checklist responses and documents through the portal, or lead details through a marketing form.
  2. 2UseData is used to run your engagement: to prepare, analyze and deliver your profit diagnostic.
  3. 3AccessReads are constrained by row-level security and role separation, so data is reachable only within its own organization and role.
  4. 4AI processingOnly minimized metadata is included in model requests; document contents and financial figures are not sent.
  5. 5Human reviewThe audit team reviews analysis and controls the publish gate before any finding or number reaches a client.
  6. 6StorageRecords are held in a managed database; uploaded files sit in private storage reachable only through short-lived signed URLs.
  7. 7RetentionData is kept for as long as it is needed for the engagement and our record-keeping, within the framework below.
  8. 8DeletionData can be soft-deleted or purged through the mechanisms described below, on request or at end of life.

Access model

Access follows a least-privilege principle: a request can reach only the data its owner and role permit, and privileged operations run on the server rather than in the browser.

AI processing

AI is applied to a deliberately minimized slice of engagement data, and never to document contents. Model requests carry labels and statuses — for example the organization name, the engagement stage, checklist labels, uploaded file names and their check verdicts — not the underlying documents or financial figures. Findings are engine output, and the portal assistant is barred from stating any numbers.

The controls around model use — the publish gate, data minimization, the metadata-only assistant, provider governance, auditability and usage caps — are described in full on our AI Governance page.

Human review & controlled writes

The step that puts a number in front of a client is a human, server-side action — not something a model or a browser session can do on its own.

Vendor data flows

We share the minimum necessary data with the service providers that process it on our behalf. The table below is a summary; the authoritative, current list is our Subprocessors page.

ProviderPurposeDataClass
VercelWeb + serverless hostingRequests, funnel API payloadsCritical
SupabaseDatabase, Auth, file Storage, Edge FunctionsAll application dataCritical
AnthropicAI model provider (Claude Haiku 4.5)Minimized engagement metadataCritical (AI)
Meta (Facebook)Pixel + Conversions API — ad measurementHashed contact data + technical idsMarketing (funnel)
TypeformFunnel lead formLead form responsesMarketing (funnel)
CalendlyFunnel call schedulingName / email / time on bookingMarketing (funnel)
Google FontsServes the Inter webfontVisitor IP (no cookie)CDN

Core application data is hosted with Supabase in the United States (AWS us-east-1); other processing locations are provider-dependent — see our Subprocessors page. Marketing providers apply to the funnel pages only and are separate from the client application.

Ownership & export

You own the data you provide. The documents you upload and the information you submit remain yours; we process them to deliver your engagement, and we do not sell your personal information.

Published deliverables and reports are provided to you as part of the engagement. Where applicable, you can request a copy of the information we hold about you by contacting us. A self-serve export tool is not offered today, so we handle these requests directly.

Encryption & transport

We describe transport protection at this level deliberately and do not claim specific ciphers or key lengths.

Retention

We keep information for as long as it is needed to run your engagement and to meet our record-keeping and advertising-measurement needs. Rather than publish fixed day counts we cannot yet commit to, we describe retention as a framework with the mechanisms that enforce it:

Retention periods vary by data category and business requirement. Alpha Scaling is formalizing category-specific retention schedules.

Deletion

Two deletion mechanisms exist in the platform:

To request access to, correction of, or deletion of your data, email edward@alpha-scaling.com.

Contact & legal details

Data questions, access & deletion

Contact edward@alpha-scaling.com for data, privacy, vendor or subprocessor questions.

Alpha Scaling’s corporate legal details — including our registered legal entity name, address, and governing-law jurisdiction — are being finalized and will be stated in our Terms of Service once confirmed.