Security

Security you can trust.

AltOps agents sign into the systems that run your business. Here is how AltOps Cloud protects what they touch, and where our compliance program stands today.

Overview

Security, built into the platform.

AltOps owns the platform and stands behind its security: the controls, the compliance program, and the accountability, all in one place.

01

Isolated per company, per person

Every company runs in its own environment. Every person inside it gets a private execution pod with its own storage. Nothing is shared with, reused for, or visible to another client.

02

Encrypted end to end

AES-256 encryption at rest for the database and for each person's storage volume. Credentials are held in a secret store, referenced by pointer, and decrypted only inside the pod that uses them.

03

Never used to train a model

Client data reaches a model provider only as the working context of a run, under commercial terms that exclude training. We do not fine-tune on it, and one client's data never improves another's agents.

04

US infrastructure

All customer data sits on US-based infrastructure. A contractual US-only residency commitment is available. Dedicated infrastructure is available for clients who require it.

05

Numbers come from code, not a model

Parsing, arithmetic, matching and threshold tests are deterministic software. The model navigates and handles exceptions. It never computes or restates a figure, so it cannot change one.

06

Every run recorded

Each step, a screenshot of every screen touched, every tool call, the rules and model version in force, and any human intervention. The record is frozen at run time and cannot be rewritten.

Compliance

SOC 2, in process with Thoropass.

We are working with Thoropass, an established compliance and audit firm. Type I first, establishing the control set at a point in time, followed by the Type II observation window.

Audit partner

SOC 2 Type I, then Type II

Our readiness assessment and vendor security questionnaire are available to your review team on request.

ThoropassIn progress

A third-party penetration test is scheduled within the SOC 2 program, with the summary letter shareable on request. Internal security reviews run on every release, covering access control, tenant scoping, input handling and credential exposure.

What security teams ask us

Not yet. We are actively in our SOC 2 process with Thoropass, an established compliance and audit firm. Type I comes first, then the Type II observation window.

No. Client information reaches the model provider only as the working context of a run, under commercial API terms where submitted data is not used for training. We never fine-tune on client data or use one client's data to improve another's agents.

Each company runs in its own isolated environment, and each person in it gets a private execution pod with its own storage. Separation is enforced in the infrastructure, in the application, and in the database itself with row-level security. There is no shared memory or knowledge across clients.

On US-based infrastructure. If you need a contractual US-only residency commitment, we will make it. For clients who require it, we also deploy on dedicated infrastructure so your data never touches shared AltOps systems.

Yes, line by line. Every run stores each step, a screenshot of every screen the agent touched, every tool call with its inputs and outputs, the rules and model version in force, and any human intervention. That record cannot be rewritten later.

Run the review before you sign.

Bring your security team to the workflow demo. We will walk through the architecture, share our SOC 2 status, and complete your questionnaire.

Book a review