trust center

Trust you can verify.

Two questions, and they're different: whether Aleq should be let near your ledger, and whether the company behind it holds up. Here's the evidence for both — attestations first, because that's what your review opens with.

attestations

Where we stand on attestations.

It's the first thing an enterprise review asks for, so it goes first — not buried under an argument about what attestations don't cover.

SOC 2

We don't publish a status on this page. Ask, and you get the straight answer: which report we hold, what period it covers, or that we don't hold one yet. No status here means ask, not assume.

Penetration test

An annual external test by an independent security firm. Executive summary available under NDA.

Control monitoring

Automated monitoring runs continuously against our controls. Drata is named for it on our subprocessor list, which is public.

SIG and CAIQ questionnaires, architecture notes, and the reports we hold go out under NDA from the document room below.

trust it on your books

The controls on your ledger.

A clean report says a company runs its controls. It doesn't stop a wrong entry from posting. These four do.

read-only start

It starts read-only.

Aleq connects to your banks, billing, and ledger read-only. It can see transactions; it cannot move a dollar, change a setting, or initiate a payment. You revoke access any time.

no payment authority

It never moves money.

Approved payments are staged for your own bank rails — you release them. Aleq has no payment authority at all, and a changed vendor bank detail freezes payment until a person verifies it.

signed actions

Every action is signed.

Each entry posts with a signed action ID and a payload hash, verified on read. The trail shows what posted, why, what triggered it, and who approved it — checkable independently, not a screenshot.

sealed periods

Closed months can't change.

A locked period is sealed with a cryptographic digest over its posted lines. Reopening it is a separate, logged action. Nothing — not even Aleq — rewrites a period you've signed.

trust the company

The vendor-risk surface.

Whether Aleq is a responsible custodian of your data. Standard, necessary, and what the attestations up top cover — a different question from what happens to your books.

HIPAA · BAA availableGDPR + CCPAPCI-DSS · no card data storedAES-256 · TLS 1.3SSO · SCIM · MFA

Encryption

AES-256-GCM at rest with per-tenant keys in AWS KMS; TLS 1.3 in transit.

HIPAA

BAA available for healthcare customers; per-tenant isolation for covered data.

GDPR + CCPA

DPA available pre-sales, with the EU representative listed.

PCI-DSS

No cardholder data stored — tokenized by a PCI-Level-1 processor at capture.

Access

SAML / OIDC SSO, SCIM provisioning, per-action RBAC, MFA on privileged actions.

Resilience

Encrypted backups, 24/7 monitoring, and a published incident-response SLA.

The full disclosure — signatures, key management, vulnerability disclosure, incident response — is on the security page.

document room

Everything your review needs.

Penetration test summaryLatest third-party assessment
Security questionnaireSIG / CAIQ format
Data processing agreementGDPR + CCPA, EU representative listed
Business associate agreementFor HIPAA-covered customers
Subprocessor listEvery vendor that touches data
Architecture overviewData flow, isolation, key management

Requests come with a mutual NDA. We reply the same day.

We close last month read-only, with your security team watching.

Every control on this page is in the room — the read-only connection, the approval gates, the signed trail. You revoke access the moment we hang up.