Trust & Security

Your data is engineered to stay yours.

How Alphorix protects workspaces, leads, agents and admins — end to end.

How we protect your data

Six pillars — audited, not marketing copy.

Encryption everywhere

TLS 1.2+ for every request in transit. AES-256 encryption at rest for databases, object storage and backups. Secrets are stored in an isolated key management system, never in code.

Workspace isolation

Every customer runs on a logically isolated workspace. All queries are scoped by workspace ID at the middleware layer, so your leads and pipeline data are inaccessible to any other tenant.

Least-privilege access

Role-based access controls, brute-force lockout on the login endpoint (5 failed attempts → 15-minute cooldown per IP + account), and time-bound access reviews. Alphorix personnel access customer workspaces only when strictly required and with an audit trail.

Hardened infrastructure

Hosted on tier-1 cloud providers running in ISO 27001 / SOC 2-certified data centers. OWASP-recommended HTTP security headers (HSTS, X-Frame-Options DENY, nosniff, Referrer-Policy, Permissions-Policy, COOP/CORP) are enforced on every response, and public endpoints are rate-limited at the application layer.

Continuous backups

Point-in-time database snapshots taken every hour with 30-day retention. Backups are encrypted at rest and restore drills are run quarterly.

Audit logging

Every sensitive action inside the CRM — logins, lead exports, user changes, permission grants — is captured in an immutable audit log available to workspace admins.

Controls at a glance

Every control on this list is live today.

Where a formal certification is in progress rather than complete, we say so — you'll never see "compliant" where we mean "working on it".

TLS 1.2+ in transit
AES-256 at rest
Row-level workspace scoping
Password hashing (bcrypt)
Brute-force lockout (5 attempts / 15 min)
Per-IP rate limiting on public endpoints
HSTS + X-Frame-Options DENY
Nosniff, Referrer-Policy, Permissions-Policy
Hourly encrypted backups
30-day backup retention
Immutable audit log
WAF & DDoS mitigation
Vulnerability disclosure programme
Sub-processor register on request
Data Processing Addendum on request
Data-subject request workflow
Compliance posture

Built to slot into your compliance programme.

GDPR & UK GDPR

Alphorix acts as your data processor and honours data-subject requests (access, correction, deletion, portability). A Data Processing Addendum is available on request.

SOC 2 aligned

Our internal controls follow the AICPA SOC 2 Trust Services Criteria (Security, Availability, Confidentiality). Formal certification is on our 2026 roadmap.

PCI DSS scope

Cardholder data is handled exclusively by Stripe. Alphorix never sees or stores full card numbers — we only retain the last 4 digits and card brand for display.

Regional data residency

For customers with data-residency requirements we can provision workspaces in specific regions on annual plans. Contact legal@alphorix.net for details.

Incident response

A live incident playbook, not a PDF in a drawer.

When something breaks or a security event is suspected, our on-call engineer follows a documented, drilled runbook. Impacted customers are notified as soon as scope is confirmed — never later than 72 hours from confirmation, in line with GDPR.

Report a vulnerability →
Response SLA
  • Acknowledge report< 1 business day
  • Triage & severity< 3 business days
  • Critical fix window< 7 days
  • Customer notice on breach< 72 hours
Frequently asked

Questions your CISO will ask.

Ready to move your leads into a safer home?

Start on the free trial — every security control on this page is enabled from day one, on every plan.

Alphorix

The CRM built for forex brokers, prop firms and financial marketing teams. Route leads, run pipeline, ship growth.

Abu Dhabi office
Abu Dhabi
United Arab Emirates
London office
Level 1, One Mayfair Place
Mayfair, London, W1J 8AJ
United Kingdom
Risk Disclaimer

Alphorix.net does not provide, solicit, or facilitate the trading of foreign exchange (forex), contracts for difference (CFDs), or any other leveraged financial products.

Trading forex and CFDs carries a high level of risk and may not be suitable for all investors. You could sustain a loss of some or all of your initial investment; therefore, you should not invest money that you cannot afford to lose. Before deciding to trade, you should carefully consider your investment objectives, level of experience, and risk appetite. Past performance is not indicative of future results.

Any references to third-party brokers, trading platforms, or financial products appearing via Alphorix.net (including lead capture forms, landing pages, and campaigns operated by our clients) are the sole responsibility of the respective advertisers and are not endorsed by Alphorix. Alphorix makes no representations regarding the regulatory status, performance, or suitability of any advertised service. Please seek independent, licensed professional advice before engaging with any financial service.

Nothing on this website constitutes investment advice, a solicitation, or an offer to buy or sell any security or financial instrument in any jurisdiction where such an offer would be unlawful.

© 2026 Alphorix. All rights reserved.