Security

Security overview

How Alakili separates one customer's data from another's, who can reach what, and where our certifications actually stand rather than where we would like them to be.

Contents

Last updated 30 August 2026

[01]

Where we actually are

SOC 2 Type I is in progress and not yet awarded. An external penetration test is booked for Q4 2026. Neither is finished, and this page says so rather than implying a certification we do not hold.

Everything below is in place today and can be evidenced on a call.

[02]

The tenancy model

Every row in the database carries an organization, and most carry a station. Every query is scoped by both on the server, not by the interface. Hiding a button is a courtesy; a refused request is the boundary.

Our data isolation page describes how that is enforced and what we do to keep it from ever being optional.

[03]

Getting in

Sign-in is email one-time codes, two-factor authentication and Google sign-in. There is no shared password and no default account.

Inside a workspace, access is decided by permissions rather than by role names, and scoped station by station. Roles are yours to author, which is why we never branch on the name of one.

[04]

Data in transit and at rest

TLS 1.3 in transit. Encrypted at rest, including backups. Credentials for the outbound channels you configure are stored encrypted and are never shown back to you in full once saved.

[05]

Amazon access

We never hold your Amazon credentials. The browser extension reads exports from the session already open in your browser, which is the whole reason it is an extension rather than a server-side scraper with your password in it.

[06]

Audit trail

Every change is recorded against the person who made it, across the whole workspace, for the life of the workspace. It cannot be pruned from inside the product, because an audit trail a customer can edit is not evidence of anything.

[07]

AI access

An assistant reaches your workspace only through a key somebody issued, and it can only ever do what the person who issued that key is permitted to do. Revoking the key revokes the access immediately, and everything it did is in the same audit trail as everything else.

[08]

People and process

Access to production is limited to the engineers who need it and is logged. Changes ship through review and an automated suite covering the tenancy rules specifically, because a scoping bug is the failure that matters most here.

[09]

Reporting something

Send it to hello@alakili.com. We will acknowledge within one business day. We will not pursue anybody who reports in good faith and gives us a reasonable chance to fix the issue before publishing it.

Question about any of this?

Procurement questions get a straight answer on the call, and anything we cannot answer there we come back on in writing.

Log in