Security
AES-256-GCM encryption, Row-Level Security isolation for every team, and SOC 2 controls with the audit underway. This page covers what we do, what we never do, and exactly who touches your data.
SOC 2 Type I
Audit in progress, target Q2 2026
SOC 2 Type II
Audit planned, target Q3 2026
ISO 27001
Controls implemented
GDPR
Compliant, US-hosted (AWS Oregon), EU on request
Compliance tables answer auditors. This answers the question teams actually ask us: “What are you going to do with our data?”
Your meetings, docs, and roadmaps are never used to train AI models. Not ours, not anyone's. The AI providers we use are contractually prohibited from training on your data.
We make money one way: subscriptions. Your data is not our product, and there is no version of our business where selling or sharing it helps us.
Row-Level Security isolates every workspace at the database layer. Your unannounced project cannot leak into another team's account.
Access to production data is restricted and MFA-gated, and every privileged action lands in a tamper-evident audit log we can show you.
Self-service account deletion removes your content from our systems. No support ticket, no retention games.
Enterprise teams can run Aligned as a dedicated deployment in their own cloud. Your infrastructure, your keys, our software.
Ask about private deploymentAligned was built by a developer who spent a decade shipping God of War titles under NDA at Sony Santa Monica. We know exactly what a leaked codename costs, because we lived with that risk on every project. This product exists to protect your team's time, not to harvest its ideas.
Measurable security controls we can demonstrate on request
User data tables with Row-Level Security
All user data protected at database level
AES-256-GCM + Vault encryption
Defense in depth for all tokens
For all admin access
Multi-factor authentication required
Audit log integrity
SHA-256 hash-chain verification
Comprehensive security controls across every layer of our platform
All subprocessors maintain independent security certifications
| Vendor | Purpose | Compliance | DPA |
|---|---|---|---|
| Clerk | Authentication | SOC 2 Type II | View |
| Supabase | Database & Storage | SOC 2 Type II | View |
| AWS | Hosting & Storage | SOC 2 Type II | View |
| OpenAI | AI Processing | SOC 2 Type II | View |
| Anthropic | AI Processing | SOC 2 Type II | View |
| AssemblyAI | Transcription | SOC 2 Type II | View |
| Stripe | Payment Processing | PCI DSS Level 1 | View |
| Gmail & Calendar | SOC 2 Type II | View | |
| Microsoft | Teams Integration | SOC 2 Type II | View |
| Atlassian | JIRA Integration | SOC 2 Type II | View |
| Slack | Messaging Integration | SOC 2 Type II | View |
| Zoom | Meeting Intelligence | SOC 2 Type II | View |
| LiveKit | Voice & Video | SOC 2 Type II | View |
| Mem0 | AI Memory | SOC 2 Type I | View |
| ElevenLabs | Voice Synthesis | SOC 2 Type II | View |
Clerk
Authentication
Supabase
Database & Storage
AWS
Hosting & Storage
OpenAI
AI Processing
Anthropic
AI Processing
AssemblyAI
Transcription
Stripe
Payment Processing
Gmail & Calendar
Microsoft
Teams Integration
Atlassian
JIRA Integration
Slack
Messaging Integration
Zoom
Meeting Intelligence
LiveKit
Voice & Video
Mem0
AI Memory
ElevenLabs
Voice Synthesis
We're happy to complete security questionnaires, answer detailed questions, and provide additional documentation for enterprise evaluations.
Typical response time: within 24 hours
Ready to see how Aligned Tools can help your team?
Schedule a Security Review