Security at AlertOwl

We handle your business emails with the same care you would. Here is exactly how we protect your data.

๐Ÿ”’ GDPR Compliant Active
๐Ÿ›ก๏ธ TLS 1.2+ Active
๐Ÿ” OAuth 2.0 Active
๐Ÿ—„๏ธ AES-256 Active
๐Ÿ“‹ CASA Tier 2 Planned
๐Ÿข SOC 2 Planned

How we protect your data

๐Ÿ”‘

No Passwords Stored

We connect to Gmail and Outlook using OAuth 2.0 tokens with read-only permissions. We never see, store, or ask for your email password.

๐Ÿงน

Content Masking

Email body content is permanently removed immediately after AI classification. Only metadata (sender, subject) and the classification result are retained.

๐Ÿ”’

Encryption Everywhere

All connections use TLS 1.2+. Database storage is encrypted with AES-256 at rest. OAuth tokens are additionally encrypted at the application level using AES-256-GCM before storage.

๐Ÿข

Tenant Isolation

Row-Level Security (RLS) on every database table ensures no customer can ever access another customer's data. Enforced at the database level.

๐Ÿ“…

Configurable Retention

You control how long we keep your data. Default is 30 days. Delete your account anytime and all data is permanently purged within 7 days.

๐Ÿค–

AI Privacy

Classification is powered by Claude (Anthropic) with zero data retention on their API. Your emails are never used to train AI models.

Our sub-processors

Every third-party service that touches your data, listed with their security certifications.

Vendor Purpose Data Access Certifications
Supabase Database All stored data SOC 2HIPAA
DigitalOcean Server hosting Data in transit SOC 2ISO 27001
Anthropic AI classification Email content (transient) SOC 2Zero retention
Twilio WhatsApp alerts Phone numbers, alert text SOC 2ISO 27001
Stripe Billing Payment info PCI DSS L1SOC 2
Cloudflare DNS + CDN Routing metadata SOC 2ISO 27001
Resend Email delivery Email addresses SOC 2

Download our documents

Enterprise prospects and customers can self-serve.

Compliance roadmap

GDPR Compliance

Privacy Policy, Terms of Service, Data Processing Agreement, configurable data retention, content masking, right to deletion.

โœ“ Active

Infrastructure Security

TLS encryption, AES-256 at rest, OAuth 2.0, Row-Level Security, automated backups, Sentry monitoring.

โœ“ Active

Google CASA Tier 2

Cloud Application Security Assessment for Gmail API verification. Third-party security audit via authorized lab.

Target: Q3 2026

SOC 2 Type I

Independent audit of security controls by a certified CPA firm. Point-in-time assessment.

Target: Q1 2027

SOC 2 Type II

Extended audit demonstrating operational effectiveness over 3-12 months.

Target: Q3 2027

ISO 27001

International information security management certification for global enterprise readiness.

Target: 2028

Questions about security?

We're happy to discuss our security practices, provide policies, or answer vendor security questionnaires.