SOC 2 Type II
Continuous control monitoring in place; independent CPA audit to be engaged. Report available under NDA on completion.
Security and governance
Alvary is built for work where an answer must be checked, defended, and traced back to its source. We state clearly where we are certified, where we are aligned, and where work is still in progress.
Certifications and alignment
We publish our certification status rather than imply more than we hold. Updated as audits complete.
Continuous control monitoring in place; independent CPA audit to be engaged. Report available under NDA on completion.
Control set implemented and mapped against Annex A; management-system formalisation in progress ahead of a certification audit.
Customer data processed in the EU. Data Processing Addendum and transfer terms provided during procurement.
Nigeria Data Protection Act alignment; §41 cross-border transfer controls in active development.
AI governance controls aligned to the standard; formal Annex A control mapping in progress.
How the platform protects work
Firm and client data stay out of model-training pipelines. We don't sell or share inputs back to model vendors for training under any default configuration.
Important actions are controlled by role, matter access, budget, and risk level. Deliverable exports and client-facing steps require explicit human review.
Legal answers, findings, and drafts retain links to underlying documents, paragraph anchors, and authorities. Unsourced claims are marked — never silently rewritten.
Important actions, exports, and permission decisions are recorded so your team can review what happened, who approved it, and why.
Data handling
TLS 1.2+ in transit; AES-256 at rest, with keys held in a managed key vault. Customer-managed keys on the enterprise roadmap.
Customer data is processed in the EU today. US and Africa regions available for enterprise engagements on request.
Customer-controlled retention windows per matter and per artifact class. Hard delete on request.
SSO via OIDC; SCIM provisioning; per-matter access controls below the tenant boundary.
Audit logs can be exported to your security tools. Important AI and workspace actions carry a signed event id.
Published list of subprocessors with purpose and processing location. Notice on changes.
Reporting
Email security@alvary.ai. We acknowledge reports within three business days and triage within ten. Researchers acting in good faith under our disclosure policy have our commitment that we will not pursue or support legal action over their research. Contact details are also published at /.well-known/security.txt per RFC 9116.
For data-protection enquiries, including a copy of the Data Processing Addendum, email privacy@alvary.ai. Our subprocessor list is published and we give notice before it changes.
We send a security brief, sample DPA, and architecture overview to qualified firms and in-house teams under NDA.