Security · Privacy · Compliance

Enterprise-grade security, without the enterprise red tape.

Alsona protects every prospect, conversation, and reply with the same rigor you'd expect from your CRM, your data warehouse, and your bank, all in one outreach platform.

Trusted, certified, audited
SOC 2 Type II
Audited annually
ISO 27001
Certified ISMS
GDPR
EU compliant
CCPA
California compliant
HIPAA-ready
BAA available
Pen-tested
Quarterly by third parties
The Alsona stack

Defense in depth, end to end.

Every layer of Alsona is hardened. From the keys protecting your data, to the people who write the code, to the runbooks we follow when things go wrong.

Encryption

  • TLS 1.3 for all data in transit
  • AES-256 at rest, including backups
  • Hardware-backed key management
  • Customer-managed keys on Enterprise

Identity & access

  • SSO via SAML 2.0 and OIDC
  • 2FA enforced for all admins
  • Role-based permissions, least privilege
  • SCIM provisioning on Enterprise

Data handling

  • Configurable data residency
  • One-click export and deletion
  • Field-level retention policies
  • Zero use of your data for model training

Monitoring

  • 24/7 intrusion detection
  • Continuous dependency scanning
  • Real-time anomaly alerts
  • Immutable audit logs

People & process

  • Mandatory annual security training
  • Background checks for all employees
  • Documented incident response plan
  • Vendor risk reviews on every processor

Resilience

  • 99.9% uptime SLA on Enterprise
  • Geographically redundant backups
  • Point-in-time recovery up to 30 days
  • Tested disaster recovery runbooks
Our promises

Three commitments we'll never break.

01

We never sell your data

Your pipeline data, prospect lists, and reply content stay yours. We don't sell, syndicate, or share with third-party data brokers.

02

We don't train models on your content

AI features run on dedicated, opted-in tenancy. Your messages, prospects, and outcomes are never used to train shared models.

03

We give you the keys

Export everything, anytime. Delete it permanently with a single API call. No retention quirks, no hostage data.

Working with procurement?

We'll send your team the SOC 2 Type II report, DPA, security questionnaire responses, and anything else they need to greenlight Alsona.