AI-assisted business audits · reviewed by humans

Trust Center

Trust at Alpha Scaling

Security, privacy, AI governance, and human oversight for AI-assisted business audits.

Last updated 25 September 2026

On this page

Explore the Trust Center

Everything a security or procurement reviewer needs, in one place. Each area links to the detail behind it.

Product trust model

Alpha Scaling delivers AI-assisted business audits. Here is the path your information takes — from what you share to the findings you receive — and where humans stay in control.

1

Customer information

Your intake answers and the business documents you upload.

2

Secure application workflow

Information enters the platform over encrypted connections; files are stored privately and access is scoped to your organization.

3

Structured processing

Uploads are validated server-side and turned into structured inputs for analysis.

4

AI-assisted analysis

Our analysis engine, with AI assistance on minimized data, proposes and scores potential findings.

5

Auditor review

The audit team reviews findings and decides what is sound enough to publish. Nothing reaches you automatically.

6

Audit findings

Only published findings become visible on your dashboard — the single source of client-facing numbers.

What “audit” means here

An Alpha Scaling audit is an operational and financial profit diagnostic — a structured look at where a business is leaking margin. It is not a statutory, GAAP, or financial-statement audit, and not an attestation. See Audit Integrity.

This is a conceptual overview of how information flows, not a description of our infrastructure.

Data categories

What the audit platform holds, and how each category is handled — who can reach it, whether AI-assisted features process it, and where a human reviews it.

Account & profile

Purpose: Your login, role, and organization.
Access: You and audit staff.
AI processing: Organization name only.
Human review: Staff manage accounts.

Organization info

Purpose: Identify your company and engagement.
Access: You and audit staff.
AI processing: Name only.
Human review: Yes.

Engagement metadata

Purpose: Run and track the audit — status, dates, day target.
Access: You and audit staff.
AI processing: Status and timeline.
Human review: Yes.

Audit intake & checklist

Purpose: Capture your inputs (the questionnaire).
Access: You and audit staff.
AI processing: Labels and status only.
Human review: Yes.

Handled as sensitive

Uploaded business documents

Purpose: Source material for the audit.
Access: You and audit staff; private storage, signed-URL only.
AI processing: Contents are not sent to the assistant; processed server-side by the engine.
Human review: Validated on upload, then staff review.

Document-check verdicts

Purpose: Automated validation of uploaded files.
Access: You and audit staff.
AI processing: Verdict label only.
Human review: Yes; checks are deterministic.

Audit findings

Purpose: The diagnostic result — leak zones, dollar ranges, confidence.
Access: Staff until published, then you.
AI processing: Engine-produced and zone-scored.
Human review: Publish gate plus audit-team estimate.

Deliverables, messages & activity log

Purpose: Reports, communication, and an append-only audit trail.
Access: You and audit staff; deliverables private until published.
AI processing: Not used.
Human review: Staff publish and manage.

Retention is a framework, not a fixed clock

We keep information for as long as needed to deliver and support your engagement and meet record-keeping needs; specific retention is governed by a data-lifecycle framework rather than published fixed periods. Deletion is available through document soft-delete and full organization purge — see Privacy and Data Governance.

Marketing lead data submitted through our funnel (name, email, phone, company, revenue bracket, and fleet size) is handled separately from the audit platform for advertising measurement. See Privacy and Cookies.

Security principles

Our security program is organized around a set of pillars. Each is detailed on our Security page.

Identity

Authenticated sessions through Supabase Auth (password and magic-link). Requests are verified server-side before privileged actions run. Security →

Authorization

Row-Level Security is enabled and forced on every table with default-deny, scoped to your user and organization. Client and staff/auditor roles are separated, and sensitive writes go through controlled server-side routines. Security →

Data protection

Encrypted in transit (TLS). Files live in private storage reachable only through short-lived signed URLs. Encryption at rest is provided by our infrastructure providers. Security →

Infrastructure

Managed hosting on Vercel and Supabase. Privileged operations run in server-side functions, never in the browser, and secrets are held in environment configuration only. Security →

Auditability

An append-only event log records platform activity; client-visible events are whitelisted. Security →

Application security

Uploads are validated server-side with deterministic checks. Inbound webhooks are verified with HMAC-SHA256 (timing-safe) and processed idempotently. Security →

AI security

AI context is scoped to your own organization. Only minimized metadata is sent to the model — never document contents or financial figures — and prompts and outputs are not persisted beyond a minimal audit record. Security →

Operational security

Internal security reviews inform ongoing improvements, privileged writes are restricted to trusted server-side processes, and the platform processes no payment-card data. Security →

Privacy

Our privacy approach is built into how the platform works, not bolted on:

Full detail is in our Privacy Policy and Subprocessors list.

AI governance

AI is an analytical tool that operates inside defined workflows — not the decision-maker. Our analysis engine produces findings from your data and a maintained knowledge base; an AI model assists analysis and powers an in-panel status-and-process assistant. Our AI-assisted features use Anthropic’s Claude (Haiku 4.5). We take a risk-based approach to AI governance.

Human review remains. AI output can be imperfect, so findings are reviewed by the audit team and pass a publish gate before any client sees them. The assistant is barred from producing findings, dollar figures, or benchmarks.

Providers are vendor-risk dependencies. The AI provider is a critical subprocessor governed by our vendor due diligence, and the data sent to it is minimized to engagement metadata — never document contents or financials.

More detail is on our AI Governance page; the provider relationship is described on Subprocessors.

Security framework approach

Alpha Scaling designs its security program with relevant SOC 2 Trust Services Criteria in mind — principally Security, Availability, and Confidentiality. This is a design orientation: it does not mean every criterion is satisfied, and we do not claim that all Trust Services Criteria are met.

Alpha Scaling designs its security program with relevant SOC 2 Trust Services Criteria in mind. Alpha Scaling does not currently represent itself as holding a SOC 2 attestation unless explicitly stated otherwise.

No third-party penetration test or independent audit has been performed to date; internal security reviews are conducted. See our Security page for the controls behind this approach.

Privacy framework approach

We are GDPR-conscious and design to support applicable privacy obligations. Where EU or UK personal data is involved, we consider the obligations that apply — data minimization, purpose limitation, controlled access, and honoring data-subject requests where the law grants them.

This is a privacy-by-design orientation, not a certification: there is no “GDPR certification,” and we do not claim one. Some formal legal details, including our legal entity and registered address, are being finalized and will be published here once confirmed.

See our Privacy Policy for how this applies in practice.

Human oversight

AI assists. Humans remain accountable.

No audit finding — and no dollar figure — reaches a client automatically. Machine analysis can propose and quantify findings, but a person decides what is published.

This is enforced in the product, not just intended:

In short: AI-assisted analysis, reviewed and published by the audit team. More on Audit Integrity and AI Governance.

Vendor due diligence

Evaluating Alpha Scaling as a vendor? We are glad to walk enterprise and security reviewers through our security architecture, privacy practices, AI governance, and subprocessor list, and to respond to a security questionnaire.

Talk to us about a review

Contact edward@alpha-scaling.com.

Related pages: Subprocessors · Security · AI Governance · Data Governance.