AI-assisted business audits · reviewed by humans

Security & AI Governance

Security & AI Governance Overview

A single-page overview of how Alpha Scaling protects accounts, documents, and AI-assisted analysis — written for security and procurement reviewers. It describes what is implemented today and is honest about what we do not claim.

Last updated 25 September 2026

1. Product overview

Alpha Scaling delivers AI-assisted business audits for established service businesses. An engagement combines a structured intake and uploaded business documents with a versioned analysis engine and a maintained knowledge base; AI assists the analysis; and the audit team reviews and publishes the findings a client sees.

The client platform is available only to authenticated accounts — nothing in it is served to anonymous visitors. A fuller walk-through is on How it works, and the trust program is summarized on the Trust Center.

What “audit” means here

An Alpha Scaling audit is an operational and financial profit diagnostic — a structured look at where a business is leaking margin. It is not a statutory, GAAP, or financial-statement audit, and not an attestation. See Audit Integrity.

2. Data categories

What the platform holds, and how each category is handled:

Marketing lead data submitted through our funnel (name, email, phone, company, revenue bracket, and fleet size) is handled separately from the audit platform for advertising measurement. See Privacy and Cookies.

3. Architecture overview

This is a conceptual description of how the system is organized. It intentionally omits hostnames, addresses, and other operational detail.

Conceptual data flow

1

Business

An established service business engages Alpha Scaling for an audit.

2

Secure structured intake

Intake answers and business documents enter the platform over encrypted connections; files are stored privately and scoped to the organization.

3

Alpha Scaling processing

Uploads are validated server-side and turned into structured inputs for analysis.

4

Analysis engine

A versioned engine and knowledge base evaluate the structured inputs against benchmarks and playbooks.

5

AI-assisted analysis

AI assists on minimized data; potential findings are proposed and scored.

6

Human audit review

The audit team reviews findings and decides what is sound enough to publish. Nothing reaches a client automatically.

7

Publication gate

A finding becomes visible only once it is explicitly published for the client's own organization.

8

Client findings

Only published findings appear on the client dashboard — the single source of client-facing numbers.

Conceptual overview of how information flows, not a description of our infrastructure.

4. Identity & access

Least privilege is a core design principle. Every request is authorized on the server against the caller's verified identity, not against values supplied by the browser.

5. Organization isolation

Tenants (organizations) are isolated in the database itself, not only in application code.

6. File security

7. Auditability

Because the product itself is an audit, traceability is built in.

How analysis is reviewed before it reaches a client is described on Audit Integrity.

8. AI architecture

AI is an analytical tool that operates inside defined workflows — not the decision-maker. Our AI-assisted features use Anthropic's Claude (Haiku 4.5). We take a risk-based approach to AI governance.

Full detail is on AI Governance.

9. Human review & publish gate

AI assists. Humans remain accountable.

No audit finding — and no dollar figure — reaches a client automatically. Machine analysis can propose and quantify findings, but a person decides what is published.

In short: AI-assisted analysis, reviewed and published by the audit team. More on Audit Integrity.

10. AI data handling

11. Subprocessors

Core application data (database, storage, and authentication) is hosted with Supabase in the United States (AWS us-east-1). Other processing locations are provider-dependent.

ProviderRoleProcessing region
SupabaseDatabase, authentication, file storage, and server-side functionsUnited States (us-east-1)
VercelWeb and serverless hostingProvider-dependent
AnthropicAI model provider (Claude Haiku 4.5) for AI-assisted featuresProvider-dependent
MetaAdvertising measurement — marketing funnel onlyProvider-dependent
TypeformMarketing lead form — funnel onlyProvider-dependent
CalendlyCall scheduling — funnel onlyProvider-dependent
Google FontsServes the Inter webfontProvider-dependent

The full, current list is on Subprocessors.

12. Privacy approach

Privacy is built into how the platform works, not bolted on. We are GDPR-conscious and design to support applicable privacy obligations; this is a privacy-by-design orientation, not a certification.

Full detail is in our Privacy Policy and Data Governance page.

13. Security framework approach

Our controls are informed by relevant SOC 2 Trust Services Criteria — principally Security, Availability, and Confidentiality. This is a design orientation: it does not mean every criterion is satisfied, and no attestation is claimed.

Alpha Scaling designs its security program with relevant SOC 2 Trust Services Criteria in mind. Alpha Scaling does not currently represent itself as holding a SOC 2 attestation unless explicitly stated otherwise.

No third-party penetration test or independent audit has been performed to date; internal security reviews are conducted. See Security for the controls behind this approach.

14. Known certification status

We are honest about our current status. We do not hold, and do not claim, any third-party security or privacy certification.

SOC 2

No SOC 2 attestation is held or claimed. Our program is designed with relevant Trust Services Criteria in mind.

ISO 27001

Not certified. We hold no ISO 27001 certification.

GDPR

Privacy controls are designed to support applicable obligations. There is no “GDPR certification,” and none is claimed.

Penetration test

No third-party penetration test has been performed to date; internal security reviews are conducted.

We hold no HIPAA or PCI certification, and the platform processes no payment-card data.

15. Security contact

Security & vendor review

Email edward@alpha-scaling.com for security questions, vendor due diligence, or to report a vulnerability. See our Responsible Disclosure policy for what to include and what to expect.

Related: Trust Center · Security · Control Summary · How it works · AI Governance · Audit Integrity · Subprocessors.