Review your spend without vendor-account integrations.
AlignCube processes the stack and spend information you enter to help you make keep/cut decisions — it does not require access to your vendor accounts. Here is exactly what we store, who processes it, how it is protected, and the controls you keep — written plainly, because the honest version is the useful one.
What we store — and what we never touch
The stack, evidence, and free text you enter can contain names, contract details, and other business information, so treat it as sensitive — do not paste passwords, API keys, or card data. Sharing you control: invited organization members see your shared stack records, and any public share link is a bearer link that anyone with the URL can view until it expires (7 days) or you revoke it. When you invoke AI-powered AlignCube features, relevant content runs through Anthropic's commercial API. Anthropic's commercial API does not use inputs or outputs to train models by default.
Where it lives
AlignCube runs on Railway (SOC 2 Type II certified infrastructure). Data is encrypted at rest at the storage layer and encrypted in transit with TLS on every connection. Each account’s audit data is isolated per customer.
Subprocessors
| Provider | Role | What it sees |
|---|---|---|
| Railway | Application hosting (US) | Application data at rest (SOC 2 Type II infrastructure) |
| Anthropic | AI analysis | Relevant content for AI-powered AlignCube features you invoke. Anthropic's commercial API does not use inputs or outputs to train models by default. |
| Stripe | Payments (PCI-DSS Level 1) | Payment details; AlignCube never sees your card number |
| Cloudflare | DNS, TLS, CDN | Encrypted traffic in transit |
| Resend | Transactional email | Your email address and the messages we send you |
| GitHub | Backup storage | Encrypted database backups (access-controlled, MFA-protected, founder-only; retained up to 90 days, then they expire) |
| PostHog | Product analytics (conditional) | Only when analytics is enabled: page/feature usage events — never audit contents, tool lists, or pasted data |
This table matches the processor list in our Privacy Policy — one canonical list, two pages. We will update it and email account owners at least 14 days before adding a new subprocessor.
Access & application controls
- Multi-factor authentication on every infrastructure account we operate (hosting, payments, code, DNS). Customer-account MFA is on the product roadmap; today customer logins use rate-limited email + password over HTTPS-only sessions.
- Production access limited to the founder; no third-party contractors touch customer data.
- Per-account data isolation, admin surfaces separately gated, session cookies HTTPS-only.
- Login rate limiting with lockout, per-visitor request limits, CSRF origin checks, request-size caps, and outbound-request (SSRF) protections.
- Daily backups with a tested restore procedure — we verify recovery, not just backup.
Your controls
- Export everything, any time: one-click full data export (GDPR Art. 20) from your Plan page — it works even after you downgrade.
- Account deletion: account deletion removes active AlignCube data after billing closes and cancels any active subscription (GDPR Art. 17). Limited backups and records required for security, tax, or legal obligations follow the Privacy retention schedule, and deletions are re-applied if a backup is ever restored — a deleted account stays deleted.
- No lock-in by design: your data is yours, in portable formats.
Continuity
AlignCube is founder-operated, so here is the continuity answer in writing rather than implied: daily backups are restore-tested; your full export is self-serve at all times and uses portable formats (usable without AlignCube); and our Terms commit that if we ever wind the Service down, you get at least 30 days' notice, a pro-rata refund of any prepaid period, and a working export path throughout. Your governance record cannot be stranded.