Security and data handling
You trust us with the most sensitive documents in your company. This is what happens to them, where they live, who else touches them, and what we never do.
Data handling
What happens to a document between the moment you upload it and the moment you delete it.
TLS 1.2 or above secures every connection, including document upload and export.
AES-256. Documents, analyses and exports are stored in Cloudflare R2 with server-side encryption enabled by default. R2 is the only durable store. Aligntra runs no separate application database, so there is no second copy of your documents to secure.
Every stored object is prefixed by organisation. The prefix is the authorisation boundary, derived from the session and never from a caller-supplied value.
Customer documents are never used to train or fine-tune any model. Document text passes through the model during analysis and is not retained by the provider afterwards.
Email security@aligntra.com and we remove your documents, analyses and account data within 30 days, then confirm in writing when it is done. Billing records are retained only as required by law.
Deletion is carried out by hand today rather than from a self-serve control.
Application logs may include document names and finding summaries. Our log aggregator, Grafana Cloud, holds them for 14 days. Sentry holds stack traces and PostHog holds usage events, neither of which carries document content.
Your documents and analyses persist until you delete them.
Access
Who can get in, and what happens when someone asks for data that is not theirs.
Clerk manages identity and sessions, with session expiry. Aligntra never sees or stores your password.
You can turn it on from your account settings. Enrolment, backup codes and account recovery are handled by our identity provider.
Available on Enterprise. We connect SAML to your identity provider when you ask for it, as part of onboarding.
A request for another organisation's data returns the same response as data that does not exist. Existence itself is not disclosed.
Where your data lives
We would rather tell you exactly where your data lives than promise regions we do not run yet.
United States
Documents and analyses live in Cloudflare R2 in the US, encrypted at rest. Model analysis runs in US regions.
European Union
EU data residency is planned. If it is a requirement for your team, tell us. It moves the roadmap.
Subprocessors
The third parties we use, what they do, where they store data, and what they touch.
| Provider | Purpose | Region | Data touched |
|---|---|---|---|
| Cloudflare R2 | Document and analysis storage | US | Full QMS documents, analyses |
| Model inference | Document analysis | US | Document text during analysis. Not stored, never used for training |
| Railway | Application hosting | US | All application data in transit |
| Clerk | Authentication and identity | US | Email, name, org membership |
| Stripe | Billing | US | Email, subscription tier. Card details never reach Aligntra |
| Sentry | Error tracking | US | Stack traces, no document content |
| Grafana Cloud | Application logs | US | Log lines, may include document names. 14-day retention |
| PostHog | Product analytics | US | Usage events, email, org id. No document content |
| Resend | Transactional email | US | Email address and recipient name |
| Drive import (OAuth) and web fonts | US / global | Drive files you select. Visitor IP on font load | |
| Cal.com | Demo scheduling on /book | US / EU | Prospect name, email, meeting details |
| Termly | Cookie consent management | US | Consent choices, visitor IP |
| Cloudflare | CDN, DDoS protection and visitor analytics | Global edge | Page content, cached. Page views and visitor IP via Cloudflare Web Analytics |
We give at least 30 days' notice before adding a subprocessor that handles personal data. This list is the same one referenced in our privacy policy.
Certifications
We do not hold SOC 2 or ISO 27001 today, and we will say so for as long as it is true.
What we can put in front of your procurement team instead: the controls above, the named subprocessor list, and a completed security questionnaire.
We will pursue SOC 2 when a customer requires it. If that is you, say so and it moves up the list.
Reporting a vulnerability
If you find a vulnerability in aligntra.com, email security@aligntra.com. We will not pursue legal action against researchers who report in good faith and give us time to fix the issue before publishing.
We acknowledge reports within two business days and keep you updated until the issue is closed. We do not publish a fixed resolution deadline, because we would rather meet the commitment we make than publish a shorter one.
What we never do
- Train models on your documents, now or as a future option
- Share your documents or findings with another customer, in any form
- Claim a certification we do not hold
- Sell, rent or broker any data you upload
Send us your questionnaire
We answer TPRM and security questionnaires before any pilot.