On this page
Explore the Trust Center
Everything a security or procurement reviewer needs, in one place. Each area links to the detail behind it.
Security & controls
Security
Security Overview
Controls
Security FAQ
Responsible Disclosure
AI & audit method
Data & legal
Product trust model
Alpha Scaling delivers AI-assisted business audits. Here is the path your information takes — from what you share to the findings you receive — and where humans stay in control.
Customer information
Your intake answers and the business documents you upload.
Secure application workflow
Information enters the platform over encrypted connections; files are stored privately and access is scoped to your organization.
Structured processing
Uploads are validated server-side and turned into structured inputs for analysis.
AI-assisted analysis
Our analysis engine, with AI assistance on minimized data, proposes and scores potential findings.
Auditor review
The audit team reviews findings and decides what is sound enough to publish. Nothing reaches you automatically.
Audit findings
Only published findings become visible on your dashboard — the single source of client-facing numbers.
An Alpha Scaling audit is an operational and financial profit diagnostic — a structured look at where a business is leaking margin. It is not a statutory, GAAP, or financial-statement audit, and not an attestation. See Audit Integrity.
This is a conceptual overview of how information flows, not a description of our infrastructure.
Data categories
What the audit platform holds, and how each category is handled — who can reach it, whether AI-assisted features process it, and where a human reviews it.
Account & profile
Purpose: Your login, role, and organization.
Access: You and audit staff.
AI processing: Organization name only.
Human review: Staff manage accounts.
Organization info
Purpose: Identify your company and engagement.
Access: You and audit staff.
AI processing: Name only.
Human review: Yes.
Engagement metadata
Purpose: Run and track the audit — status, dates, day target.
Access: You and audit staff.
AI processing: Status and timeline.
Human review: Yes.
Audit intake & checklist
Purpose: Capture your inputs (the questionnaire).
Access: You and audit staff.
AI processing: Labels and status only.
Human review: Yes.
Handled as sensitive
Uploaded business documents
Purpose: Source material for the audit.
Access: You and audit staff; private storage, signed-URL only.
AI processing: Contents are not sent to the assistant; processed server-side by the engine.
Human review: Validated on upload, then staff review.
Document-check verdicts
Purpose: Automated validation of uploaded files.
Access: You and audit staff.
AI processing: Verdict label only.
Human review: Yes; checks are deterministic.
Audit findings
Purpose: The diagnostic result — leak zones, dollar ranges, confidence.
Access: Staff until published, then you.
AI processing: Engine-produced and zone-scored.
Human review: Publish gate plus audit-team estimate.
Deliverables, messages & activity log
Purpose: Reports, communication, and an append-only audit trail.
Access: You and audit staff; deliverables private until published.
AI processing: Not used.
Human review: Staff publish and manage.
We keep information for as long as needed to deliver and support your engagement and meet record-keeping needs; specific retention is governed by a data-lifecycle framework rather than published fixed periods. Deletion is available through document soft-delete and full organization purge — see Privacy and Data Governance.
Marketing lead data submitted through our funnel (name, email, phone, company, revenue bracket, and fleet size) is handled separately from the audit platform for advertising measurement. See Privacy and Cookies.
Security principles
Our security program is organized around a set of pillars. Each is detailed on our Security page.
Identity
Authenticated sessions through Supabase Auth (password and magic-link). Requests are verified server-side before privileged actions run. Security →
Authorization
Row-Level Security is enabled and forced on every table with default-deny, scoped to your user and organization. Client and staff/auditor roles are separated, and sensitive writes go through controlled server-side routines. Security →
Data protection
Encrypted in transit (TLS). Files live in private storage reachable only through short-lived signed URLs. Encryption at rest is provided by our infrastructure providers. Security →
Infrastructure
Managed hosting on Vercel and Supabase. Privileged operations run in server-side functions, never in the browser, and secrets are held in environment configuration only. Security →
Auditability
An append-only event log records platform activity; client-visible events are whitelisted. Security →
Application security
Uploads are validated server-side with deterministic checks. Inbound webhooks are verified with HMAC-SHA256 (timing-safe) and processed idempotently. Security →
AI security
AI context is scoped to your own organization. Only minimized metadata is sent to the model — never document contents or financial figures — and prompts and outputs are not persisted beyond a minimal audit record. Security →
Operational security
Internal security reviews inform ongoing improvements, privileged writes are restricted to trusted server-side processes, and the platform processes no payment-card data. Security →
Privacy
Our privacy approach is built into how the platform works, not bolted on:
- Data minimization — AI-assisted features receive only metadata such as file names and statuses, not the contents of your documents or your financials.
- Purpose limitation — information is used to deliver and support your audit engagement; funnel data is used for advertising measurement and kept separate.
- Controlled access — access is scoped by organization and role through forced Row-Level Security, with private, signed-URL-only file storage.
- Retention — governed by a data-lifecycle framework rather than fixed published periods.
- Deletion — document soft-delete and full organization purge are available on request.
- Vendor management — we share the minimum necessary with a short, verified list of subprocessors.
- Your rights — where your region grants data-protection rights (for example the EU/UK or California), you can exercise them by contacting us.
Full detail is in our Privacy Policy and Subprocessors list.
AI governance
AI is an analytical tool that operates inside defined workflows — not the decision-maker. Our analysis engine produces findings from your data and a maintained knowledge base; an AI model assists analysis and powers an in-panel status-and-process assistant. Our AI-assisted features use Anthropic’s Claude (Haiku 4.5). We take a risk-based approach to AI governance.
Human review remains. AI output can be imperfect, so findings are reviewed by the audit team and pass a publish gate before any client sees them. The assistant is barred from producing findings, dollar figures, or benchmarks.
Providers are vendor-risk dependencies. The AI provider is a critical subprocessor governed by our vendor due diligence, and the data sent to it is minimized to engagement metadata — never document contents or financials.
More detail is on our AI Governance page; the provider relationship is described on Subprocessors.
Security framework approach
Alpha Scaling designs its security program with relevant SOC 2 Trust Services Criteria in mind — principally Security, Availability, and Confidentiality. This is a design orientation: it does not mean every criterion is satisfied, and we do not claim that all Trust Services Criteria are met.
Alpha Scaling designs its security program with relevant SOC 2 Trust Services Criteria in mind. Alpha Scaling does not currently represent itself as holding a SOC 2 attestation unless explicitly stated otherwise.
No third-party penetration test or independent audit has been performed to date; internal security reviews are conducted. See our Security page for the controls behind this approach.
Privacy framework approach
We are GDPR-conscious and design to support applicable privacy obligations. Where EU or UK personal data is involved, we consider the obligations that apply — data minimization, purpose limitation, controlled access, and honoring data-subject requests where the law grants them.
This is a privacy-by-design orientation, not a certification: there is no “GDPR certification,” and we do not claim one. Some formal legal details, including our legal entity and registered address, are being finalized and will be published here once confirmed.
See our Privacy Policy for how this applies in practice.
Human oversight
No audit finding — and no dollar figure — reaches a client automatically. Machine analysis can propose and quantify findings, but a person decides what is published.
This is enforced in the product, not just intended:
- Publish gate — a finding that has not been published is invisible to the client by design; access rules return only published findings, and only for the client’s own organization.
- Assistant barred from numbers — the in-panel assistant is explicitly prevented from producing findings, dollar amounts, or benchmarks.
- Findings only from published rows — any number you see comes from a published finding reviewed by the audit team, never from the assistant.
In short: AI-assisted analysis, reviewed and published by the audit team. More on Audit Integrity and AI Governance.
Vendor due diligence
Evaluating Alpha Scaling as a vendor? We are glad to walk enterprise and security reviewers through our security architecture, privacy practices, AI governance, and subprocessor list, and to respond to a security questionnaire.
Talk to us about a review
Contact edward@alpha-scaling.com.
Related pages: Subprocessors · Security · AI Governance · Data Governance.