Run Free Audit
Security

Review your spend without vendor-account integrations.

AlignCube processes the stack and spend information you enter to help you make keep/cut decisions. It does not require access to your vendor accounts. Here is exactly what we store, who processes it, how it is protected, and the controls you keep, written plainly, because the honest version is the useful one.

No vendor OAuth grants to manage
Encrypted in transit and at rest (storage layer)
Not used to train models by AlignCube
Self-serve export and account deletion

Two promises a competitor cannot copy

Encryption and isolation are table stakes: necessary, and everyone claims them. These two are structural, and they are the reason a number from AlignCube is worth showing to Finance.

No inflated captured claims

Every reviewable amount is capped at the tool’s known monthly cost. Unconfirmed amounts stay reviewable, never captured, since captured reflects an outcome a person recorded as complete.

Reviewable$1,326
To cut$690
Captured$0
Sample stack, eight tools. Three figures, never collapsed into one. The gap between them is the work still to do.

No vendor commissions

No commissions, referral fees, kickbacks or paid placement, from any tool AlignCube scores. A cut recommendation costs us nothing and earns us nothing.

Nothing in the pricing model prefers one verdict over another.

What we store, and what we never touch

What we store
Tool names, costs, owners, and the company context you enter or paste
Your audit results, decisions, and evidence notes
Your account email
What we never touch
Your card number: payments run entirely through Stripe
Vendor logins or SSO credentials: AlignCube does not require vendor-account access
Your data for AlignCube model training: AlignCube does not use audit data to train models

The stack, evidence, and free text you enter can contain names, contract details, and other business information, so treat it as sensitive. Do not paste passwords, API keys, or card data. Sharing you control: invited organization members see your shared stack records, and any public share link is a bearer link that anyone with the URL can view until it expires (7 days) or you revoke it. When you invoke AI-powered AlignCube features, relevant content runs through Anthropic's commercial API. Anthropic's commercial API does not use inputs or outputs to train models by default.

Where it lives

AlignCube runs on Railway (SOC 2 Type II certified infrastructure). Data is encrypted at rest at the storage layer and encrypted in transit with TLS on every connection. Each account’s audit data is logically separated per account in the application.

Subprocessors

ProviderRoleWhat it sees
RailwayApplication hosting (US)Application data at rest (SOC 2 Type II infrastructure)
AnthropicAI analysisRelevant content for AI-powered AlignCube features you invoke. Anthropic's commercial API does not use inputs or outputs to train models by default.
StripePayments (PCI-DSS Level 1)Payment details; AlignCube never sees your card number
CloudflareDNS, TLS, CDNEncrypted traffic in transit
ResendTransactional emailYour email address and the messages we send you
GitHubBackup storageDatabase backups (access-controlled, MFA-protected, founder-only; retained up to 90 days, then they expire)
GoogleMailboxes and web fontsMessages you send to our support and founder inboxes (Google Workspace); your IP address and browser details when a page loads Google Fonts; your email address and our messages only if the backup email route is used
PostHogProduct analytics (conditional)Only when analytics is enabled: page/feature usage events, never audit contents, tool lists, or pasted data

This table matches the processor list in our Privacy Policy: one canonical list, two pages. We will update it and email account owners at least 14 days before adding a new subprocessor.

Access & application controls

Evidence & data flow

The full life of your data, in plain language:

Retention and deletion rules for all of the above are in Your controls, directly below.

Your controls

Continuity

AlignCube is founder-operated, so here is the continuity answer in writing rather than implied: daily backups are restore-tested; your full export is self-serve at all times and uses portable formats (usable without AlignCube); and our Terms commit that if we ever wind the Service down, you get at least 30 days' notice, a pro-rata refund of any prepaid period, and a working export path throughout. Your governance record cannot be stranded.

Where we are honestly at: AlignCube is an early-stage product and has not yet completed its own SOC 2 audit (it is on the roadmap as we grow). Our infrastructure provider is SOC 2 Type II certified. If your review needs a signed DPA or a completed security questionnaire, email [email protected] and we will work through it with you. You will hear back within one business day.
Security review, questionnaire, or DPA? Email [email protected] and a human (the founder) answers. Found a vulnerability? Same address, and thank you: we take reports seriously and respond quickly.