About Alpha Scaling
What is Alpha Scaling?
Alpha Scaling delivers AI-assisted business audits. A structured analysis engine and a maintained knowledge base process the business information you submit, AI assists that analysis, and a human audit team reviews and publishes what you see — delivered through a secure client portal. AI supports the work; it is not the whole audit. See our Trust Center and Audit Integrity page.
What type of audit is this?
An operational and financial-performance diagnostic — a structured review that looks for recoverable profit leakage across a defined set of operational zones. It is not a statutory, regulated, or GAAP financial-statement audit, not an attestation or assurance engagement, and Alpha Scaling is not a CPA or registered public accounting firm. Nothing in our reports is an opinion on your financial statements. See Audit Integrity.
Does Alpha Scaling process financial information?
Yes. Engagements involve operational and financial documents and data that you upload. These are treated as sensitive: they are held in private storage, validated server-side, and processed by our analysis engine. Their contents are not sent to the AI assistant — only minimized metadata such as file names and statuses is. See Security and Data Governance.
AI & human oversight
Does Alpha Scaling use AI?
Yes. Alpha Scaling uses AI to assist its audit workflow. A structured analysis engine processes the business information you submit, and an AI model supports that analysis and an in-panel status-and-process assistant. AI is one tool inside a defined workflow — it is not the whole audit. See our AI Governance page.
Does AI make final audit decisions?
No. AI assists analysis; it does not decide or publish findings. Findings are produced by our analysis engine from your data and knowledge base, reviewed by the audit team, and held behind a publish gate — no finding is visible to a client until a person publishes it. The in-panel assistant is explicitly barred from producing findings, dollar figures, or benchmarks. See AI Governance.
Are uploaded financial documents sent to the AI assistant?
No. The contents of uploaded documents are processed server-side by our analysis engine and are never sent to the AI assistant. The assistant receives only minimized engagement metadata — file names, statuses, and labels — not document contents or financial figures. See AI Governance.
Does Alpha Scaling use human auditors?
Yes. AI assists, but humans remain accountable. Client-facing findings are subject to a controlled publication workflow, and our audit process includes human review before findings are finalized for client use — client-facing numbers come only from published findings. More on Audit Integrity.
Which third-party AI providers are used?
Anthropic. We use Anthropic’s Claude (Haiku 4.5) for AI-assisted features. Anthropic is a critical AI subprocessor; the data it receives is minimized to engagement metadata such as file names and statuses — not document contents or financial figures. See Subprocessors and AI Governance.
Is customer data used to train AI models?
We do not send your customer data to AI providers for the purpose of training their models. The data we send for AI-assisted features is minimized to engagement metadata and is used to perform the requested analysis. A provider’s own model-training practices are governed as a vendor-risk matter through our subprocessor due diligence; we describe that relationship on Subprocessors rather than make guarantees on a provider’s behalf. See also AI Governance.
Data & access
What business data is processed?
On the audit platform: your account and profile, organization details, engagement metadata (status, dates, targets), intake and checklist responses, uploaded business documents, automated document-check verdicts, audit findings, deliverables, messages, and an append-only activity log. Uploaded documents are treated as sensitive — their contents are processed server-side by our engine and are not sent to the assistant. Marketing lead data from our funnel is handled separately. See the data categories on our Trust Center and our Privacy Policy.
How are organizations separated?
Each organization’s data is isolated at the database layer by Row-Level Security that is enabled and forced on every table, with a default-deny posture. Access policies are scoped to the caller’s own user and organization (auth.uid()), and client and staff/auditor roles are separated. A request sees nothing unless a policy explicitly grants it. See Security.
How are files stored?
Uploaded files are held in private storage buckets that are not publicly accessible, and are served only through short-lived signed URLs. Every upload first passes a deterministic, server-side validation step before it is accepted. See Security.
Who can see findings?
The audit team can see findings while an engagement is in progress; a client sees a finding only after a staff member publishes it, and then only within the client’s own organization. This is enforced in the database: access rules return only published findings, scoped to the client’s organization. See Audit Integrity.
Are findings automatically exposed to clients?
No. A finding is invisible to the client until the audit team publishes it. There is a code-enforced publish gate, and the in-panel assistant cannot produce findings or dollar figures — so no raw AI-produced conclusion reaches a client automatically. See AI Governance and Audit Integrity.
Who can access customer data?
Access is controlled by Row-Level Security that is forced on every table with default-deny, scoped to your user and organization, with separation between client and staff/auditor roles. Files are private and reachable only through short-lived signed URLs, privileged operations run server-side, and secrets are held in environment configuration only. See Security.
Which third parties process data?
A short, verified list. Core hosting and data: Vercel (web and serverless hosting) and Supabase (database, authentication, file storage, and functions; core application data is hosted in the United States). AI: Anthropic (Claude Haiku 4.5), which receives minimized metadata only. Our separate marketing funnel additionally uses Meta, Typeform, and Calendly for lead capture and ad measurement. Purposes and data locations are detailed on our Subprocessors page.
How can a customer request deletion?
Email edward@alpha-scaling.com. The platform supports document soft-delete and full organization purge. Retention is governed by a data-lifecycle framework rather than fixed published periods. See Privacy and Data Governance.
Compliance & due diligence
Is Alpha Scaling SOC 2 certified?
No.
Alpha Scaling designs its security program with relevant SOC 2 Trust Services Criteria in mind. Alpha Scaling does not currently represent itself as holding a SOC 2 attestation unless explicitly stated otherwise.
We design toward relevant SOC 2 Trust Services Criteria (principally Security, Availability, and Confidentiality), but we do not currently hold or represent a SOC 2 attestation. No third-party penetration test or independent audit has been performed to date; internal security reviews are conducted. See Security, our Security Overview, and our Controls matrix.
How does Alpha Scaling handle GDPR?
We are GDPR-conscious and design to support applicable privacy obligations; there is no “GDPR certification,” and we do not claim one. Where EU or UK personal data is involved we consider the obligations that apply — data minimization, purpose limitation, controlled access, and honoring data-subject requests where the law grants them. Some formal legal details, including our legal entity and registered address, are being finalized and will be published once confirmed. Contact edward@alpha-scaling.com. See Privacy.
How do I report a security issue?
Email edward@alpha-scaling.com, or read our Responsible Disclosure policy for what to include and what to expect. We welcome good-faith reports from the security community.
How can a company conduct vendor due diligence?
Email edward@alpha-scaling.com. We can walk enterprise and security reviewers through our security architecture, privacy practices, AI governance, and subprocessor list, and respond to a security questionnaire. For a control-level view, start with our Security Overview and Controls matrix. Related: Security, AI Governance, Privacy, and Subprocessors.
Still have a question?
Contact edward@alpha-scaling.com.