generated: '2026-08-11' method: searched probe: true source: https://runalphaloops.com/security url: https://trust.runalphaloops.com/ description: >- AlphaLoops publishes a security page at https://runalphaloops.com/security and operates a Vanta-hosted Trust Center at https://trust.runalphaloops.com/ (linked from the site footer). The Trust Center returned HTTP 200 but is fully client-rendered — no certification names, control list, or document index are present in the served HTML, and the Vanta trust-page API paths probed anonymously return the SPA shell rather than JSON. The certifications below are therefore read from the PUBLIC SECURITY PAGE, not from the Trust Center itself. # IMPORTANT — these are the claims as WORDED by the provider. AlphaLoops describes itself as # "aligned with" ISO 27001 and built on "SOC 2 certified infrastructure". That is a posture # statement about controls and about its cloud vendors; it is NOT an assertion that AlphaLoops # itself holds a SOC 2 or ISO 27001 certificate, and no audit report, certificate number, or # auditor is named on any public page. Recorded verbatim so the distinction is not lost. certifications: - name: SOC 2 Type II claim: infrastructure status: claimed-alignment verbatim: 'SOC 2 Type II infrastructure' certificate_published: false note: >- Stated as the compliance posture of the underlying infrastructure. No SOC 2 report, certificate, or auditor is named on a public page, and the Trust Center that would normally host the report is not machine-readable. - name: ISO 27001 claim: aligned status: claimed-alignment verbatim: 'ISO 27001 aligned controls' certificate_published: false note: Described as "aligned with" / "aligned controls" — not stated as a held certification. - name: NIST Cybersecurity Framework claim: aligned status: claimed-alignment verbatim: 'NIST Cybersecurity Framework' certificate_published: false - name: COBIT claim: aligned status: claimed-alignment verbatim: 'COBIT governance domains' certificate_published: false # Privacy regimes named on the pricing page against the contact-data add-on. privacy_regimes: - name: GDPR verbatim: 'GDPR and CCPA compliant' source: https://runalphaloops.com/pricing - name: CCPA verbatim: 'GDPR and CCPA compliant' source: https://runalphaloops.com/pricing security_program: penetration_testing: cadence: weekly provider: Intruder.io methodology: OWASP coverage: - Web applications & APIs - Infrastructure endpoints - OWASP Top 10 vulnerabilities - Emerging threat detection remediation_sla: critical: 7 days high: 14 days medium: 30 days low: 90 days encryption: in_transit: TLS 1.3 at_rest: AES-256 notes: - Perfect forward secrecy - Encrypted database connections authentication: - 100% MFA enforcement across all systems - FIDO2/WebAuthn hardware key support - Phishing-resistant authentication methods - Rate limiting and account lockout protection access_control: - Row-level security (RLS) for data isolation - Least privilege access model - Quarterly access reviews - 24-hour deprovisioning SLA infrastructure: - DDoS protection via Cloudflare - Web Application Firewall (WAF) - Network segmentation - API rate limiting monitoring: - Real-time security event logging - Anomaly detection systems - Automated threat response - Comprehensive audit trails data_minimization: >- "Only process DOT numbers - no sensitive personal or financial data" — as published. Note this sits in tension with the product's own contact-enrichment surface, which returns work email, personal emails, phone numbers and employment history for named individuals (see openapi EnrichedContact schema and the contact-credits add-on on the pricing page). evidence: - url: https://runalphaloops.com/security http_status: 200 note: Server-rendered; all certification and control claims above read from this page. - url: https://trust.runalphaloops.com/ http_status: 200 note: Vanta-hosted Trust Center; JS-rendered, no certifications present in served HTML. - url: https://runalphaloops.com/pricing http_status: 200 note: GDPR/CCPA claim against the contact-data add-on.