trust center

Trust you can verify.

There are two questions, and they're different. Can you trust the software to touch your ledger? And can you trust the company behind it? Here's what holds, in code — and the documents your security team asks for.

trust it on your books

Can you trust it to touch the ledger?

The new question — the one no attestation answers. A clean SOC 2 doesn't stop software from posting a wrong entry. These four controls do.

read-only start

It starts read-only.

Aleq connects to your banks, billing, and ledger read-only. It can see transactions; it cannot move a dollar, change a setting, or initiate a payment. You revoke access any time.

no payment authority

It never moves money.

Approved payments are staged for your own bank rails — you release them. Aleq has no payment authority at all, and a changed vendor bank detail freezes payment until a person verifies it.

signed actions

Every action is signed.

Each entry posts with a signed action ID and a payload hash, verified on read. The trail shows what posted, why, what triggered it, and who approved it — checkable independently, not a screenshot.

sealed periods

Closed months can't change.

A locked period is sealed with a cryptographic digest over its posted lines. Reopening it is a separate, logged action. Nothing — not even Aleq — rewrites a period you've signed.

trust the company

The vendor-risk surface.

Whether Aleq is a responsible custodian of your data. Standard, necessary, and where SOC 2 lives — a different question from what the software does to your books.

HIPAA · BAA availableGDPR + CCPAPCI-DSS · no card data storedAES-256 · TLS 1.3SSO · SCIM · MFA
EncryptionAES-256-GCM at rest with per-tenant keys in AWS KMS; TLS 1.3 in transit.
HIPAABAA available for healthcare customers; per-tenant isolation for covered data.
GDPR + CCPADPA available pre-sales, with the EU representative listed.
PCI-DSSNo cardholder data stored — tokenized by a PCI-Level-1 processor at capture.
AccessSAML / OIDC SSO, SCIM provisioning, per-action RBAC, MFA on privileged actions.
ResilienceEncrypted backups, 24/7 monitoring, and a published incident-response SLA.

The full disclosure — signatures, key management, vulnerability disclosure, incident response — is on the security page.

document room

Everything your review needs.

Penetration test summaryLatest third-party assessment
Security questionnaireSIG / CAIQ format
Data processing agreementGDPR + CCPA, EU representative listed
Business associate agreementFor HIPAA-covered customers
Subprocessor listEvery vendor that touches data
Architecture overviewData flow, isolation, key management

Requests come with a mutual NDA. We reply the same day.

Ready to see it hold?

Connect read-only, watch every control in action, and revoke it the moment we hang up.