Your data is engineered to stay yours.
How Alphorix protects workspaces, leads, agents and admins — end to end.
Six pillars — audited, not marketing copy.
TLS 1.2+ for every request in transit. AES-256 encryption at rest for databases, object storage and backups. Secrets are stored in an isolated key management system, never in code.
Every customer runs on a logically isolated workspace. All queries are scoped by workspace ID at the middleware layer, so your leads and pipeline data are inaccessible to any other tenant.
Role-based access controls, brute-force lockout on the login endpoint (5 failed attempts → 15-minute cooldown per IP + account), and time-bound access reviews. Alphorix personnel access customer workspaces only when strictly required and with an audit trail.
Hosted on tier-1 cloud providers running in ISO 27001 / SOC 2-certified data centers. OWASP-recommended HTTP security headers (HSTS, X-Frame-Options DENY, nosniff, Referrer-Policy, Permissions-Policy, COOP/CORP) are enforced on every response, and public endpoints are rate-limited at the application layer.
Point-in-time database snapshots taken every hour with 30-day retention. Backups are encrypted at rest and restore drills are run quarterly.
Every sensitive action inside the CRM — logins, lead exports, user changes, permission grants — is captured in an immutable audit log available to workspace admins.
Every control on this list is live today.
Where a formal certification is in progress rather than complete, we say so — you'll never see "compliant" where we mean "working on it".
Built to slot into your compliance programme.
Alphorix acts as your data processor and honours data-subject requests (access, correction, deletion, portability). A Data Processing Addendum is available on request.
Our internal controls follow the AICPA SOC 2 Trust Services Criteria (Security, Availability, Confidentiality). Formal certification is on our 2026 roadmap.
Cardholder data is handled exclusively by Stripe. Alphorix never sees or stores full card numbers — we only retain the last 4 digits and card brand for display.
For customers with data-residency requirements we can provision workspaces in specific regions on annual plans. Contact legal@alphorix.net for details.
A live incident playbook, not a PDF in a drawer.
When something breaks or a security event is suspected, our on-call engineer follows a documented, drilled runbook. Impacted customers are notified as soon as scope is confirmed — never later than 72 hours from confirmation, in line with GDPR.
Report a vulnerability →- Acknowledge report< 1 business day
- Triage & severity< 3 business days
- Critical fix window< 7 days
- Customer notice on breach< 72 hours
Questions your CISO will ask.
Ready to move your leads into a safer home?
Start on the free trial — every security control on this page is enabled from day one, on every plan.