Alethinx AI
Alethinx AI
trust
Trust Center
Security & Compliance
Built Into Every Layer
Alethinx AI is built for private equity deal teams, ETA searchers, and M&A professionals who demand enterprise-grade data security. Here's exactly how we protect your deals.
AES-256
encryption
0
data breaches
Security Data Privacy Infrastructure SLA & Uptime Compliance Vulnerability Disclosure
🔐
Security
How we protect your deal data
🔒Active
Encryption at Rest
All deal data, user records, and AI-generated insights are encrypted at rest using AES-256 at rest across all data stores.
🛡️Active
Encryption in Transit
All data in transit is protected by TLS 1.3. HTTPS is enforced across all endpoints — no exceptions. Certificate management is fully automated.
👤Active
Row-Level Security
Row-level security is enforced on all database tables. Users can only access their own deal data — cross-tenant data access is architecturally prevented.
🔑Active
Authentication
Secure session management with cryptographically signed tokens. All sessions are scoped, signed, and expire automatically. No plaintext passwords are ever stored.
🤖Active
AI Prompt Security
All AI agent prompts are server-side only — never exposed to the client. Prompt injection protections are applied across all AI inference calls. User data is never used to train external AI models.
🔍Planned
Penetration Testing
Planned, not yet scheduled. No external penetration test has been booked and no vendor is engaged. When one is, we will name the firm and publish a summary of the results here.
🕵️
Data Privacy
What we collect, how we use it, and your rights

Alethinx AI is designed with data minimization as a core principle. We collect only what is required to deliver deal intelligence services to you.

What we collect:

  • Account information (name, email, company)
  • Deal data you enter or import into the platform
  • Usage analytics (page views, feature interactions) — anonymized
  • Payment metadata via Stripe (we never see your full card number)

What we do not do:

  • We do not sell your data to third parties — ever
  • We do not use your deal data to train AI models
  • We do not allow advertisers to target you
  • We do not share your data with competitors or data brokers

Data residency: All data is stored and processed within the United States. EU users may request data residency options at privacy@alethinx.ai.

Retention: Active account data is retained for the duration of your subscription plus 90 days. On account deletion, all personal data is purged within 30 days. Deal records may be exported before deletion.

Your rights (CCPA / GDPR): You may request a full export, correction, or deletion of your data at any time by emailing privacy@alethinx.ai. We respond within 5 business days.

🏗️
Infrastructure
Our vendor stack and their security certifications
Vercel
Frontend hosting, edge CDN, serverless functions
SOC 2ISO 27001
United States / global CDN
Supabase
Managed database, authentication, and serverless infrastructure
SOC 2 Type II
United States
AI Inference Layer
Proprietary scoring and orchestration built on frontier models, powering deal analysis, agent execution, and document processing
No training on dataServer-side only
United States
Stripe
Payment processing, subscription billing, invoicing
PCI DSS L1SOC 2
Global
Make.com
Workflow automation and integration infrastructure
GDPRISO 27001
EU / US
📊
Availability Targets
Internal targets we design against. These are goals, not contractual commitments, and we do not offer service credits against them — we do not yet run the continuous monitoring that measuring them would require.
📉Not published
We do not publish uptime figures
This section previously listed per-service uptime targets, 90-day actuals, and a 10% service-credit policy. No monitoring system produced those numbers, so the actuals have been removed and the credit policy withdrawn — we do not offer service credits against targets nobody measures. The targets have gone with them rather than be restated as goals, because a percentage on a trust page reads as a measurement whatever it is labelled.

Automated checks are being wired to our health endpoint. When they report, this section will show live check results and whatever history has actually accumulated since — a short honest record rather than a long invented one.
Compliance & Certifications
Current posture and roadmap
🔐Not certified
SOC 2 Type II
SOC 2: roadmap underway. Not certified. No audit has been scheduled and no date is committed. Our infrastructure partners hold their own SOC 2 certifications; that is their certification, not ours.
🌍Active
GDPR Compliance
Data processing agreements are available on request. All user data access, export, and deletion requests are fulfilled within 5 business days via privacy@alethinx.ai.
🇺🇸Active
CCPA Compliance
California residents have full rights to access, correct, and delete their data. We do not sell personal information. Opt-out requests are honored within 15 days.
🏥Evaluating
HIPAA
Alethinx AI is a deal intelligence platform, not a healthcare data processor. HIPAA is not currently applicable. If your use case requires it, please contact us.
🐛
Vulnerability Disclosure
Found something? We want to know.

Responsible Disclosure Program

We appreciate the security community's efforts to help keep Alethinx AI safe. If you've discovered a potential security vulnerability, please report it responsibly. We commit to responding within 2 business days and resolving critical issues within 72 hours.