Trust you can verify.
Two questions, and they're different: whether Aleq should be let near your ledger, and whether the company behind it holds up. Here's the evidence for both — attestations first, because that's what your review opens with.
Where we stand on attestations.
It's the first thing an enterprise review asks for, so it goes first — not buried under an argument about what attestations don't cover.
SOC 2
We don't publish a status on this page. Ask, and you get the straight answer: which report we hold, what period it covers, or that we don't hold one yet. No status here means ask, not assume.
Penetration test
An annual external test by an independent security firm. Executive summary available under NDA.
Control monitoring
Automated monitoring runs continuously against our controls. Drata is named for it on our subprocessor list, which is public.
SIG and CAIQ questionnaires, architecture notes, and the reports we hold go out under NDA from the document room below.
The controls on your ledger.
A clean report says a company runs its controls. It doesn't stop a wrong entry from posting. These four do.
It starts read-only.
Aleq connects to your banks, billing, and ledger read-only. It can see transactions; it cannot move a dollar, change a setting, or initiate a payment. You revoke access any time.
It never moves money.
Approved payments are staged for your own bank rails — you release them. Aleq has no payment authority at all, and a changed vendor bank detail freezes payment until a person verifies it.
Every action is signed.
Each entry posts with a signed action ID and a payload hash, verified on read. The trail shows what posted, why, what triggered it, and who approved it — checkable independently, not a screenshot.
Closed months can't change.
A locked period is sealed with a cryptographic digest over its posted lines. Reopening it is a separate, logged action. Nothing — not even Aleq — rewrites a period you've signed.
The vendor-risk surface.
Whether Aleq is a responsible custodian of your data. Standard, necessary, and what the attestations up top cover — a different question from what happens to your books.
Encryption
AES-256-GCM at rest with per-tenant keys in AWS KMS; TLS 1.3 in transit.
HIPAA
BAA available for healthcare customers; per-tenant isolation for covered data.
GDPR + CCPA
DPA available pre-sales, with the EU representative listed.
PCI-DSS
No cardholder data stored — tokenized by a PCI-Level-1 processor at capture.
Access
SAML / OIDC SSO, SCIM provisioning, per-action RBAC, MFA on privileged actions.
Resilience
Encrypted backups, 24/7 monitoring, and a published incident-response SLA.
The full disclosure — signatures, key management, vulnerability disclosure, incident response — is on the security page.
Everything your review needs.
Requests come with a mutual NDA. We reply the same day.
We close last month read-only, with your security team watching.
Every control on this page is in the room — the read-only connection, the approval gates, the signed trail. You revoke access the moment we hang up.
