Trust & Security

How Aletheia protects Investigation Data across security, data residency, and compliance.

Security practices

Aletheia is built for industrial manufacturers with regulated and safety-critical operations. Core security measures include:

  • Enterprise SSO (SAML/OIDC via WorkOS) with multi-factor authentication enforced through your identity provider
  • Role-based access controls with least-privilege defaults
  • TLS 1.2 or higher encryption for all data in transit
  • Encryption at rest across database and file storage (Neon and Cloudflare)
  • Authenticated sessions via secure, HTTP-only JWT tokens
  • Bcrypt password hashing for credential storage
  • Audit trails recording user actions, with soft deletion that preserves investigation history
  • Secret scanning with push protection on our source repositories
  • Enforcing Content Security Policy and hardened security headers

Data residency & Bring Your Own Database

Every customer's Investigation Data lives in its own isolated PostgreSQL database — there is no shared multi-tenant data store. Customers choose between two deployment models:

  • Bring Your Own Database (BYODB): connect a PostgreSQL database that you host and control. Your Investigation Data stays in your infrastructure, under your retention, backup, and residency policies.
  • Managed: Aletheia provisions a dedicated, isolated database per customer on Neon, hosted in the United States (US East region).

File attachments are stored with tenant-scoped path prefixes, and tenant isolation is enforced at the database layer with application-layer controls on every request.

Subprocessors

Aletheia uses the following third-party subprocessors to deliver the platform. Material changes to this list are communicated with reasonable advance notice.

SubprocessorPurposeData touchedRegionDPA status
Vercel, Inc.Application hostingApplication requests, runtime logsUnited StatesDPA in place
Neon, Inc.PostgreSQL database hosting (isolated per-tenant databases)All Investigation DataUnited StatesDPA in place
Cloudflare, Inc. (R2)File and attachment storage (tenant-scoped prefixes)Uploaded attachmentsUnited StatesDPA in place
OpenAI, LLCAI analysis (API; not used for model training; 30-day abuse-monitoring retention)Investigation Data submitted for analysisUnited StatesDPA in place
Resend, Inc.Transactional email deliveryRecipient email addresses and message contentUnited StatesDPA in place
WorkOS, Inc.Enterprise SSO and authenticationAuthentication identifiers, SSO metadataUnited StatesDPA in place
Upstash, Inc.Rate limiting and caching (Redis)Rate-limit keys containing user identifiers and emailsUnited StatesDPA in place
Sentry (Functional Software, Inc.)Application error monitoringScrubbed error metadata (no PII or Investigation Data)United StatesDPA accepted

Compliance posture

  • 21 CFR Part 11-aware: the platform maintains audit trails and soft-deletion designed with Part 11 expectations in mind. Aletheia does not claim Part 11 certification — suitability assessment remains the customer's responsibility.
  • GAMP 5: Aletheia positions as a Category 4 (configured product) for customer validation purposes.
  • SOC 2: not yet certified; a SOC 2 audit is on our roadmap. Our security package (below) documents current controls in the meantime.

Service status

Live platform availability and incident history are published at status.aletheiarcfa.com.

Request the security package

A complete security package — including our CAIQ responses and policy set — is available to prospective and current customers under NDA. To request it, or to report a security concern, contact security@aletheiareliability.com.