How Aligntra protects your QMS.
Compliance teams trust us with the most sensitive documents in their company. Here's exactly what we do with them — and what we don't.
What we do with your data
Documents are encrypted in transit and at rest. Per-org isolation. No training on customer data. Deletion on request.
Encryption
TLS 1.3 in transit. AES-256 at rest. Cloudflare R2 for document storage with server-side encryption enabled by default.
Per-org isolation
Every document is keyed to your organization at the storage layer. Isolation between customers is structural — not role-based access alone.
No training
We do not train on customer data. Documents pass through the LLM during analysis only and are never used to improve any model.
Auth + SSO
Clerk-managed identity — we never see or store your password. SSO + SAML available on Enterprise.
Deletion on request
Email security@aligntra.com and we purge your documents, analyses, and account data. Billing records are retained only as required by law.
Logging & retention
Application logs may include document names and finding summaries; they expire after 14 days. Your documents and analyses persist until you delete them.
Who else touches your data
Every third party we use, what they do, and where they store data. DPAs available on request.
Hosted in the US. EU residency on the roadmap.
We'd rather tell you exactly where your data lives than promise regions we don't run yet.
United States
Documents and analyses live in Cloudflare R2 in the US, encrypted at rest. LLM analysis runs through our US AWS accounts on a global inference profile.
European Union
EU data residency is planned. If it's a requirement for your team, tell us — it moves the roadmap.
We answer TPRM, DPA, and security questionnaires fast.
A signed DPA, sub-processor details, and our standard security questionnaire response are available within one business day on request.