Skip to main content
SECURITY

How Aligntra protects your QMS.

Compliance teams trust us with the most sensitive documents in their company. Here's exactly what we do with them — and what we don't.

Encrypted in transit + at rest No training on customer data Per-org isolation at the storage layer
CONTROLS

What we do with your data

Documents are encrypted in transit and at rest. Per-org isolation. No training on customer data. Deletion on request.

Encryption

TLS 1.3 in transit. AES-256 at rest. Cloudflare R2 for document storage with server-side encryption enabled by default.

Per-org isolation

Every document is keyed to your organization at the storage layer. Isolation between customers is structural — not role-based access alone.

No training

We do not train on customer data. Documents pass through the LLM during analysis only and are never used to improve any model.

Auth + SSO

Clerk-managed identity — we never see or store your password. SSO + SAML available on Enterprise.

Deletion on request

Email security@aligntra.com and we purge your documents, analyses, and account data. Billing records are retained only as required by law.

Logging & retention

Application logs may include document names and finding summaries; they expire after 14 days. Your documents and analyses persist until you delete them.

SUBPROCESSORS

Who else touches your data

Every third party we use, what they do, and where they store data. DPAs available on request.

LAST UPDATED · 10 JUN 2026 Request DPA →
Provider
Purpose
Region
Data touched
Cloudflare R2
Document + analysis storage
US
Full QMS documents, analyses
Anthropic / AWS Bedrock
LLM analysis (Claude Sonnet 4.6)
US accounts · global inference profile
Document text during analysis — not stored, never used for training
Railway
Application hosting
US
All application data in transit
Clerk
Auth + identity
US
Email, name, org membership
Stripe
Billing
US
Email, subscription tier
Sentry
Error tracking
US
Stack traces (no document content)
Grafana Cloud
Application logs
US
Log lines — may include document names · 14-day retention
PostHog
Product analytics
US
Usage events, email, org id — no document content
Resend
Transactional email
US
Email + recipient name
Google
Drive import (OAuth) + web fonts
US / global
Drive files you select; visitor IP on font load
Cal.com
Demo scheduling on /book
US / EU
Prospect name, email, meeting details
Termly
Cookie consent management
US
Consent choices, visitor IP
Cloudflare
CDN + DDoS protection
Global edge
Page content (cached)
DATA RESIDENCY

Hosted in the US. EU residency on the roadmap.

We'd rather tell you exactly where your data lives than promise regions we don't run yet.

TODAY

United States

Documents and analyses live in Cloudflare R2 in the US, encrypted at rest. LLM analysis runs through our US AWS accounts on a global inference profile.

ON THE ROADMAP

European Union

EU data residency is planned. If it's a requirement for your team, tell us — it moves the roadmap.

QUESTIONS FROM YOUR PROCUREMENT TEAM?

We answer TPRM, DPA, and security questionnaires fast.

A signed DPA, sub-processor details, and our standard security questionnaire response are available within one business day on request.