Run Free Audit
Security

Review your spend without vendor-account integrations.

AlignCube processes the stack and spend information you enter to help you make keep/cut decisions — it does not require access to your vendor accounts. Here is exactly what we store, who processes it, how it is protected, and the controls you keep — written plainly, because the honest version is the useful one.

No vendor OAuth grants to manage
Encrypted in transit and at rest
Not used to train models by AlignCube
Self-serve export and account deletion

What we store — and what we never touch

What we store
Tool names, costs, owners, and the company context you enter or paste
Your audit results, decisions, and evidence notes
Your account email
What we never touch
Your card number — payments run entirely through Stripe
Vendor logins or SSO credentials — AlignCube does not require vendor-account access
Your data for AlignCube model training — AlignCube does not use audit data to train models

The stack, evidence, and free text you enter can contain names, contract details, and other business information, so treat it as sensitive — do not paste passwords, API keys, or card data. Sharing you control: invited organization members see your shared stack records, and any public share link is a bearer link that anyone with the URL can view until it expires (7 days) or you revoke it. When you invoke AI-powered AlignCube features, relevant content runs through Anthropic's commercial API. Anthropic's commercial API does not use inputs or outputs to train models by default.

Where it lives

AlignCube runs on Railway (SOC 2 Type II certified infrastructure). Data is encrypted at rest at the storage layer and encrypted in transit with TLS on every connection. Each account’s audit data is isolated per customer.

Subprocessors

ProviderRoleWhat it sees
RailwayApplication hosting (US)Application data at rest (SOC 2 Type II infrastructure)
AnthropicAI analysisRelevant content for AI-powered AlignCube features you invoke. Anthropic's commercial API does not use inputs or outputs to train models by default.
StripePayments (PCI-DSS Level 1)Payment details; AlignCube never sees your card number
CloudflareDNS, TLS, CDNEncrypted traffic in transit
ResendTransactional emailYour email address and the messages we send you
GitHubBackup storageEncrypted database backups (access-controlled, MFA-protected, founder-only; retained up to 90 days, then they expire)
PostHogProduct analytics (conditional)Only when analytics is enabled: page/feature usage events — never audit contents, tool lists, or pasted data

This table matches the processor list in our Privacy Policy — one canonical list, two pages. We will update it and email account owners at least 14 days before adding a new subprocessor.

Access & application controls

Your controls

Continuity

AlignCube is founder-operated, so here is the continuity answer in writing rather than implied: daily backups are restore-tested; your full export is self-serve at all times and uses portable formats (usable without AlignCube); and our Terms commit that if we ever wind the Service down, you get at least 30 days' notice, a pro-rata refund of any prepaid period, and a working export path throughout. Your governance record cannot be stranded.

Where we are honestly at: AlignCube is an early-stage product and has not yet completed its own SOC 2 audit (it is on the roadmap as we grow). Our infrastructure provider is SOC 2 Type II certified. If your review needs a signed DPA or a completed security questionnaire, email [email protected] and we will work through it with you — you will hear back within one business day.
Security review, questionnaire, or DPA? Email [email protected] — a human (the founder) answers. Found a vulnerability? Same address, and thank you: we take reports seriously and respond quickly.