We maintain the highest security controls to protect the integrity of our AI accountability data and respect the privacy of reporters.
ALPAR AI's hosting, policies, and systems are aligned with leading industry frameworks.
SOC 2 Type II readiness is planned. No certification has been issued yet.
Strict adherence to EU data protection principles, automatic PII masking.
Aligned with Turkish Personal Data Protection Law (No. 6698) standards.
Data resides in Frankfurt (Vercel) and Ireland (Supabase) under strict EU laws.
ISO 27001 alignment is in progress. Formal certification has not been issued yet.
Regular penetration testing and compliance with OWASP Top 10 vulnerabilities.
Our timeline for achieving additional certifications and hardening our infrastructure.
Complete formal SOC 2 Type II third-party audit and publish report.
Implement client-side encrypted whistleblower submission boxes.
Formal accreditation of our Information Security Management system.
The factual, current status of ALPAR AI's certifications and encryption controls.
SOC 2 Type II readiness is planned. No certification has been issued yet.
ISO 27001 alignment is in progress. Formal certification has not been issued yet.
Data at rest is encrypted with AES-256: secrets are stored in an application-level AES-256-GCM vault, and infrastructure is encrypted at rest by the hosting provider.
Data in transit is protected with TLS 1.3 across the platform's hosting infrastructure.
ALPAR AI is building its infrastructure in accordance with AICPA's Trust Services Criteria, focusing on Security, Availability, Processing Integrity, Confidentiality, and Privacy. We enforce strict access controls, continuous monitoring, and comprehensive audit logs across all our operational environments.
Our Information Security Management System (ISMS) is designed following ISO/IEC 27001 standards. We employ a risk-based approach to managing people, processes, and IT systems, ensuring the confidentiality and integrity of all whistleblower and incident reports.
All sensitive data at rest, including PII-masked incident records and user credentials, is protected using AES-256 encryption. Our database volumes are encrypted by default, and application-level secrets are stored in a secure, AES-256-GCM vault with strict role-based access.
We welcome reports from security researchers to help keep our platform safe. If you believe you have discovered a vulnerability, please contact our security team at security@alparai.com.
Please do not expose vulnerability details publicly until we have resolved the issue. We review all reports within 24 hours. Our security contacts and policies are verified in accordance with RFC 9116 via our official security.txt.