Security and data handling

You trust us with the most sensitive documents in your company. This is what happens to them, where they live, who else touches them, and what we never do.

Last reviewed 30 Aug 2026 security@aligntra.com

Data handling

What happens to a document between the moment you upload it and the moment you delete it.

Control How it works Status

TLS 1.2 or above secures every connection, including document upload and export.

Enforced

AES-256. Documents, analyses and exports are stored in Cloudflare R2 with server-side encryption enabled by default. R2 is the only durable store. Aligntra runs no separate application database, so there is no second copy of your documents to secure.

Enforced

Every stored object is prefixed by organisation. The prefix is the authorisation boundary, derived from the session and never from a caller-supplied value.

Enforced

Customer documents are never used to train or fine-tune any model. Document text passes through the model during analysis and is not retained by the provider afterwards.

Never

Email security@aligntra.com and we remove your documents, analyses and account data within 30 days, then confirm in writing when it is done. Billing records are retained only as required by law.

Deletion is carried out by hand today rather than from a self-serve control.

Enforced

Application logs may include document names and finding summaries. Our log aggregator, Grafana Cloud, holds them for 14 days. Sentry holds stack traces and PostHog holds usage events, neither of which carries document content.

Your documents and analyses persist until you delete them.

Enforced

Access

Who can get in, and what happens when someone asks for data that is not theirs.

Control How it works Status

Clerk manages identity and sessions, with session expiry. Aligntra never sees or stores your password.

Enforced

You can turn it on from your account settings. Enrolment, backup codes and account recovery are handled by our identity provider.

Enforced

Available on Enterprise. We connect SAML to your identity provider when you ask for it, as part of onboarding.

Enforced

A request for another organisation's data returns the same response as data that does not exist. Existence itself is not disclosed.

Enforced

Where your data lives

We would rather tell you exactly where your data lives than promise regions we do not run yet.

Today

United States

Documents and analyses live in Cloudflare R2 in the US, encrypted at rest. Model analysis runs in US regions.

On the roadmap

European Union

EU data residency is planned. If it is a requirement for your team, tell us. It moves the roadmap.

Subprocessors

The third parties we use, what they do, where they store data, and what they touch.

ProviderPurpose RegionData touched
Cloudflare R2Document and analysis storage USFull QMS documents, analyses
Model inferenceDocument analysis US Document text during analysis. Not stored, never used for training
RailwayApplication hosting USAll application data in transit
ClerkAuthentication and identity USEmail, name, org membership
StripeBilling USEmail, subscription tier. Card details never reach Aligntra
SentryError tracking USStack traces, no document content
Grafana CloudApplication logs USLog lines, may include document names. 14-day retention
PostHogProduct analytics USUsage events, email, org id. No document content
ResendTransactional email USEmail address and recipient name
GoogleDrive import (OAuth) and web fonts US / globalDrive files you select. Visitor IP on font load
Cal.comDemo scheduling on /book US / EUProspect name, email, meeting details
TermlyCookie consent management USConsent choices, visitor IP
CloudflareCDN, DDoS protection and visitor analytics Global edge Page content, cached. Page views and visitor IP via Cloudflare Web Analytics

We give at least 30 days' notice before adding a subprocessor that handles personal data. This list is the same one referenced in our privacy policy.

Certifications

We do not hold SOC 2 or ISO 27001 today, and we will say so for as long as it is true.

What we can put in front of your procurement team instead: the controls above, the named subprocessor list, and a completed security questionnaire.

We will pursue SOC 2 when a customer requires it. If that is you, say so and it moves up the list.

Reporting a vulnerability

If you find a vulnerability in aligntra.com, email security@aligntra.com. We will not pursue legal action against researchers who report in good faith and give us time to fix the issue before publishing.

We acknowledge reports within two business days and keep you updated until the issue is closed. We do not publish a fixed resolution deadline, because we would rather meet the commitment we make than publish a shorter one.

What we never do

  • Train models on your documents, now or as a future option
  • Share your documents or findings with another customer, in any form
  • Claim a certification we do not hold
  • Sell, rent or broker any data you upload

Send us your questionnaire

We answer TPRM and security questionnaires before any pilot.

Doc WEB-LP-001Rev 15Approved 30 Aug 2026 Reviewed 30 Aug 2026Owner Aligntra QC ● Controlled