Trust you can verify.
There are two questions, and they're different. Can you trust the software to touch your ledger? And can you trust the company behind it? Here's what holds, in code — and the documents your security team asks for.
Can you trust it to touch the ledger?
The new question — the one no attestation answers. A clean SOC 2 doesn't stop software from posting a wrong entry. These four controls do.
It starts read-only.
Aleq connects to your banks, billing, and ledger read-only. It can see transactions; it cannot move a dollar, change a setting, or initiate a payment. You revoke access any time.
It never moves money.
Approved payments are staged for your own bank rails — you release them. Aleq has no payment authority at all, and a changed vendor bank detail freezes payment until a person verifies it.
Every action is signed.
Each entry posts with a signed action ID and a payload hash, verified on read. The trail shows what posted, why, what triggered it, and who approved it — checkable independently, not a screenshot.
Closed months can't change.
A locked period is sealed with a cryptographic digest over its posted lines. Reopening it is a separate, logged action. Nothing — not even Aleq — rewrites a period you've signed.
The vendor-risk surface.
Whether Aleq is a responsible custodian of your data. Standard, necessary, and where SOC 2 lives — a different question from what the software does to your books.
The full disclosure — signatures, key management, vulnerability disclosure, incident response — is on the security page.
Everything your review needs.
Requests come with a mutual NDA. We reply the same day.
Ready to see it hold?
Connect read-only, watch every control in action, and revoke it the moment we hang up.
