Encrypted in transit and at rest
All traffic is encrypted in transit (HTTPS/TLS), and your data is encrypted at rest (AES-256) in our managed database and file storage.
Altrusion holds your drawings, pricing, and program data, so we hold ourselves to a simple rule: this page describes only controls that are actually in place, verified against our own code. No badge-collecting, no vague assurances, and nothing claimed that we don't do.
The safeguards below are live in production today and are exercised by automated tests, not just written down.
All traffic is encrypted in transit (HTTPS/TLS), and your data is encrypted at rest (AES-256) in our managed database and file storage.
Sign-in uses one-time email links and codes. We never store account passwords, so there are no passwords to steal.
Every request is authorized server-side against your organization — never against anything the browser supplies. We maintain an adversarial harness that signs in as one company and attempts to reach another’s data across the API, alongside an anonymous-access audit of every route.
Drawings, specs, and proposals live in private storage that is not publicly reachable. They are shared only through signed links that expire after one hour, and document access across the portal and staff systems is audit-logged.
Suppliers never see competitors’ bids, pricing, or identities. Metered directory search results are anonymized until revealed, revealed search profiles are watermarked per recipient, and agency identity is stripped from outgoing requests.
Staff systems run on a separate, separately-authenticated service. Staff dashboard endpoints require a verified staff session plus a service-to-service secret, and staff actions are attributed and audit-logged.
Altrusion is an AI-heavy product, so this deserves plain language.
We name every provider that processes customer data. No unnamed “trusted partners.”
The maintained list, and how each provider is used, lives in our Privacy Policy. We update it as our providers change.
If you have a security question, or believe you have found a vulnerability, email info@altrusion.com and we will respond promptly.