AI-assisted business audits · reviewed by humans

Security

Security at Alpha Scaling

How we protect your account, your documents, and the AI-assisted analysis behind every engagement. This page describes the controls that are implemented today, and marks the controls we are still adding.

Last updated 25 September 2026

Identity & authentication

Access to the Alpha Scaling client platform requires an authenticated account. Nothing in the platform is served to anonymous visitors.

Authorization & access control

Least privilege is a core design principle. Every request is authorized on the server against the identity of the caller, and each tenant can reach only its own data. This principle is enforced in the database itself, not only in application code:

Data protection

Data retention and the full data lifecycle are described on our Data Governance page. We do not publish specific encryption cipher details.

Application security

Authorization is always performed on the server. The browser is treated as untrusted input.

Infrastructure security

The platform runs on two managed providers: Vercel for web and serverless hosting, and Supabase for the database, authentication, file storage, and server-side functions. We rely on their infrastructure security and keep application privileges separated across these boundaries, so that a component holds only the access it needs.

The full list of providers that process data on our behalf is on our Subprocessors page.

HTTP security headers

Responses are returned with a baseline set of browser-hardening headers, so a browser enforces safe defaults on every page:

A Content-Security-Policy is being introduced in report-only mode first, so it can be validated against real traffic before it is enforced.

Secrets management

Logging & observability

Auditability

Because the product itself is an audit, traceability is built in.

How analysis is reviewed before it reaches you is described on our Audit Integrity page.

AI security

Our AI features are designed for controlled, human-in-the-loop analysis. The in-product assistant is a status and process helper; it is deliberately kept away from producing client-facing numbers.

For how we govern AI end to end, see our AI Governance page.

Vulnerability management

We continuously review the application for security issues as the platform evolves.

Incident response

We maintain a defined internal process for identifying, investigating, and responding to security incidents. If an incident affects your data, we will work to contain it and to notify affected parties where appropriate.

Security framework

The controls described above are the substance of our security program; framework language is secondary to them. Alpha Scaling uses security controls informed by relevant SOC 2 Trust Services Criteria. Alpha Scaling does not currently claim a SOC 2 attestation.

SOC 2

Alpha Scaling designs its security program with relevant SOC 2 Trust Services Criteria in mind. Alpha Scaling does not currently represent itself as holding a SOC 2 attestation unless explicitly stated otherwise.

We build security in from the start (privacy-by-design) and are honest about our current status: no third-party penetration test or independent audit has been performed to date; we conduct internal security reviews as the platform evolves. We do not hold, and do not claim, any third-party security certification.

Where we describe our program as “SOC 2-aligned,” we mean it is designed with the relevant Trust Services Criteria in mind — not that it has been independently certified. We do not currently hold SOC 2, ISO, HIPAA, or PCI certification. For a control-by-control view, see our Security Overview and Controls matrix.

Report a vulnerability

Found a security issue?

We welcome reports from the security community. Email edward@alpha-scaling.com, or read our Responsible Disclosure policy for what to include and what to expect.