Trust & Security

How Aletheia protects Investigation Data across security, data residency, and compliance.

Security practices

Aletheia is built for industrial manufacturers with regulated and safety-critical operations. Core security measures include:

  • Enterprise SSO (SAML/OIDC via WorkOS) with multi-factor authentication enforced through your identity provider
  • Role-based access controls with least-privilege defaults
  • TLS 1.2 or higher encryption for all data in transit
  • Encryption at rest across database and file storage (Neon and Cloudflare)
  • Authenticated sessions via secure, HTTP-only JWT tokens
  • Bcrypt password hashing for credential storage
  • Audit trails recording user actions, with soft deletion that preserves investigation history
  • Secret scanning with push protection on our source repositories
  • Enforcing Content Security Policy and hardened security headers

Data residency & Bring Your Own Database

Every customer's Investigation Data lives in its own isolated PostgreSQL database — there is no shared multi-tenant data store. Customers choose between two deployment models:

  • Bring Your Own Database (BYODB): connect a PostgreSQL database that you host and control. Your Investigation Data stays in your infrastructure, under your retention, backup, and residency policies.
  • Managed: Aletheia provisions a dedicated, isolated database per customer on Neon, hosted in the United States (US East region).

File attachments are stored with tenant-scoped path prefixes, and tenant isolation is enforced at the database layer with application-layer controls on every request.

AI use & governance

Aletheia uses OpenAI's API to generate analysis suggestions — follow-up questions, candidate cause trees, and draft action items. Investigation Data submitted for analysis is handled as described in the subprocessor table below: API access only, not used for model training, and subject to OpenAI's 30-day abuse-monitoring retention. Our Privacy Policy (§4) covers AI data handling in detail.

  • All AI output is a draft. An investigator must review and explicitly promote candidates before anything becomes part of the RCFA record — final records are human-authored.
  • Provenance labeling:AI-generated cause-tree nodes carry an "AI" badge in the editors and in the main RCFA report exports; human-added nodes carry the author's initials.
  • Know the limits:cause-tree nodes without a cited source represent the model's own inference and should be verified before relying on them. The platform marks cited nodes so reviewers can tell the difference.

Subprocessors

Aletheia uses the following third-party subprocessors to deliver the platform. Material changes to this list are communicated with reasonable advance notice.

SubprocessorPurposeData touchedRegionDPA status
Vercel, Inc.Application hostingApplication requests, runtime logsUnited StatesDPA in place
Neon, Inc.PostgreSQL database hosting (isolated per-tenant databases)All Investigation DataUnited StatesDPA in place
Cloudflare, Inc. (R2)File and attachment storage (tenant-scoped prefixes)Uploaded attachmentsUnited StatesDPA in place
OpenAI, LLCAI analysis (API; not used for model training; 30-day abuse-monitoring retention)Investigation Data submitted for analysisUnited StatesDPA in place
Resend, Inc.Transactional email deliveryRecipient email addresses and message contentUnited StatesDPA in place
WorkOS, Inc.Enterprise SSO and authenticationAuthentication identifiers, SSO metadataUnited StatesDPA in place
Upstash, Inc.Rate limiting and caching (Redis)Rate-limit keys containing user identifiers and emailsUnited StatesDPA in place
Sentry (Functional Software, Inc.)Application error monitoringScrubbed error metadata (no PII or Investigation Data)United StatesDPA accepted

Compliance posture

  • 21 CFR Part 11-aware: the platform maintains audit trails and soft-deletion designed with Part 11 expectations in mind. Aletheia does not claim Part 11 certification — suitability assessment remains the customer's responsibility.
  • GAMP 5: Aletheia positions as a Category 4 (configured product) for customer validation purposes.
  • SOC 2: not yet certified; a SOC 2 audit is on our roadmap. Our security package (below) documents current controls in the meantime.

Service status

Live platform availability and incident history are published at status.aletheiarcfa.com.

Request the security package

A complete security package — including our CAIQ responses and policy set — is available to prospective and current customers under NDA. To request it, or to report a security concern, contact security@aletheiareliability.com.