We hold ourselves to the same standard
A third-party risk tool that cannot answer its own questionnaire is not worth buying. Here is our posture, stated without inflation, including what we have not done.
Where we actually are
We operate in alignment with these standards today. No certification has been awarded and no audit is currently engaged. When that changes, this page changes.
SOC 2
Controls mapped to the Trust Services Criteria and operated. Not certified.
ISO/IEC 27001
Security managed against the standard. Certification sits on the roadmap.
GDPR
Data minimisation and privacy by design, with a published sub-processor list.
CSA STAR
A CAIQ v4 response is drafted. Publication follows the policy set it references.
Penetration testing
External scanning runs today. An independent penetration test is on the assurance roadmap and has not yet been performed.
Encrypted backups
Daily encrypted database backups to dedicated object storage, with a documented restore path.
Where it lives and who touches it
Hosting
Production application and database run in the EU, in Frankfurt. US hosting is available as a dedicated Enterprise deployment. UK and UAE regions are on the roadmap and are not available today.
Tenant isolation
Every tenant's data is separated at the database level with row-level security enforced on the tables, not only in application code.
Encryption
Encrypted in transit and at rest. Backups are separately encrypted before they leave the database.
Sub-processors
Render, Wasabi, OpenAI, Sentry, MailerSend and Stripe, each with its region published. See the list.
What the assistant sees, and what it never does
Altisium uses AI to draft and to grade. Here is the boundary.
Scoped to your tenant
It only ever reads the workspace of the user asking.
Runs on the OpenAI API
Listed in the sub-processor list. The API terms exclude use of submitted data for training.
Not used for training
Not by us, and not by the provider under those terms.
A human commits the score
Every AI-assisted grade is approved by a reviewer, and the approval is on the audit trail.
What you can read, and what to ask for
Published
Privacy Policy, Acceptable Use Policy, Cookie Policy, Sub-processor list, Terms.
On request
Data Processing Agreement, business continuity summary, and a completed CAIQ. Write to security@altisium.com.
Availability
We design for a 99.999% uptime target. There is no public status page yet, so this is a target rather than a measured figure.
Send us your questionnaire.
We answer our own diligence the way we expect suppliers to answer yours.
