Security & Trust

Built to be trusted with proprietary data.

Altrusion holds your drawings, pricing, and program data, so we hold ourselves to a simple rule: this page describes only controls that are actually in place, verified against our own code. No badge-collecting, no vague assurances, and nothing claimed that we don't do.

How your data is protected

Practices, not promises.

The safeguards below are live in production today and are exercised by automated tests, not just written down.

Encrypted in transit and at rest

All traffic is encrypted in transit (HTTPS/TLS), and your data is encrypted at rest (AES-256) in our managed database and file storage.

Passwordless sign-in

Sign-in uses one-time email links and codes. We never store account passwords, so there are no passwords to steal.

Tenant isolation, adversarially tested

Every request is authorized server-side against your organization — never against anything the browser supplies. We maintain an adversarial harness that signs in as one company and attempts to reach another’s data across the API, alongside an anonymous-access audit of every route.

Private documents, expiring links

Drawings, specs, and proposals live in private storage that is not publicly reachable. They are shared only through signed links that expire after one hour, and document access across the portal and staff systems is audit-logged.

Marketplace confidentiality

Suppliers never see competitors’ bids, pricing, or identities. Metered directory search results are anonymized until revealed, revealed search profiles are watermarked per recipient, and agency identity is stripped from outgoing requests.

Staff access, controlled and logged

Staff systems run on a separate, separately-authenticated service. Staff dashboard endpoints require a verified staff session plus a service-to-service secret, and staff actions are attributed and audit-logged.

Ownership and control

Your data stays yours.

You own it. You can take it. You can delete it.

  • You retain ownership of everything you submit. Our click-through agreement grants Altrusion only the limited license needed to host and process it to provide the service, and acceptance is recorded with timestamp, IP, and version.
  • We never sell your data.
  • Account admins can download a complete export of their organization's data — profile, team, RFQs, quotes, proposals, messages, and agreement records — self-service from the portal.
  • Account admins can also delete their account or content self-service, protected by an emailed confirmation code and a 30-day cooling-off period during which the deletion can be cancelled with one click. Records we are legally required to keep (for example billing and signed agreements) are retained as required by law.

Export-controlled work

  • The platform is not an ITAR enclave, and we say so plainly: controlled technical data (ITAR, EAR-restricted, CUI) must not be uploaded.
  • Every document upload requires an explicit attestation that the file contains no export-controlled data, and each attestation is recorded — who, what, and when.
  • Opportunities flagged for ITAR or export-control markers are matched only to ITAR-registered US suppliers, the flag is permanent, and controlled document packages are never attached to our outreach — suppliers are directed to the issuing agency.
AI processing

What AI sees, and what it never does.

Altrusion is an AI-heavy product, so this deserves plain language.

Inference-only AI processing

  • All AI on the platform is inference-only API calls to Anthropic (analysis, request and proposal generation, DFM review) and Voyage AI (embeddings for capability matching). Altrusion does not train or fine-tune models on identifiable customer data.
  • Anthropic’s commercial terms prohibit training their models on our API content. We maintain a subprocessor register and review each AI vendor’s retention and training terms — see the current list and details in our privacy policy.

Disclosed, not buried

  • Submitted specifications and drawings do transit these AI APIs for the features that need them — producing estimates, capability matches, and DFM analysis. This is disclosed in our agreement and privacy policy, not hidden in a footnote.
  • De-identified, aggregated data (for example, price, quantity, and specification ranges with company-identifying details removed) may be used to improve Altrusion's own estimation and benchmarking tools, as described in the platform Terms.
Subprocessors

Who touches your data, by name.

We name every provider that processes customer data. No unnamed “trusted partners.”

  • SupabaseDatabase, file storage, and authentication
  • RailwayApplication hosting
  • AnthropicAI processing of submitted text and documents (API access; not used to train Anthropic’s models)
  • Voyage AIText embeddings for capability matching
  • StripePayment processing
  • ResendTransactional email delivery
  • ExpoMobile push notification delivery
  • Microsoft 365Business email correspondence

The maintained list, and how each provider is used, lives in our Privacy Policy. We update it as our providers change.

What we don't claim

Honesty is a security control.

  • We do not currently hold SOC 2, ISO 27001, or any third-party security certification, and we won't imply otherwise. The controls on this page are real and enforced, but they have not yet been independently audited.
  • No method of transmission or storage is completely secure. We tell you what we do — we don't promise the impossible.
  • Hardening is ongoing. Current work includes database-enforced row-level isolation as a second layer beneath the application checks described above, and finer-grained internal access roles. As independent audits and certifications are completed, this page will say so — and not before.

Questions, or something to report?

If you have a security question, or believe you have found a vulnerability, email info@altrusion.com and we will respond promptly.