Security & trust
Alex serves cities, schools, employers, and community organizations, and some of what they entrust to us is sensitive. We operate a SOC 2-aligned control framework across the platform, and for engagements that warrant it we can operate any build under our full audit-ready program from day one.
Our security posture, plainly
We maintain controls aligned to the AICPA Trust Services Criteria (the SOC 2 framework) across security, availability, and confidentiality. That is a statement about how we build and operate, not a certification: a SOC 2 report is issued by an independent CPA firm after an audit, and we engage that process per project when a client's requirements call for it. If your procurement needs a SOC 2 report, ask us; the readiness work is already done, which makes the attestation a scheduling decision rather than a rebuild.
Controls in operation today
Access. Production surfaces are gated: enterprise identity (Auth0) on member portals, scoped access codes on partner surfaces, and contract-gated provisioning on licensed modules. Sessions use hardened cookie settings; administrative actions are logged.
Change management. Every application is version-controlled with a full change history. Our most critical files run under a canon governance protocol: modifications require an explicit typed override, and file hashes are verified against a baseline on a recurring schedule.
Data protection. TLS everywhere; strict security headers (CSP, HSTS, frame denial) on hardened surfaces; secrets in environment configuration, never in code; data minimization by design, including zero-retention patterns on our most sensitive tools and aggregation floors on small-population statistics.
Evidence and audit trails. Where documentation matters most, we use append-only, hash-chained ledgers so records are tamper-evident and every export carries verifiable provenance.
Availability. Independent external uptime monitoring with alerting, health-check endpoints on every service, scheduled backups with documented restore runbooks, and recovery-time objectives per system class.
Vendors. A small, reviewed set of subprocessors (hosting, identity, email, analytics) documented in our vendor register with a risk tier for each.
What "SOC 2 mode" means for your project
When an engagement warrants attestation-grade posture, we apply our SOC 2 build checklist from the first commit: scoped access reviews, audit logging on authentication and administrative events, rate limiting, pinned dependencies, backup wiring, and an incident-response runbook naming real people. The control framework, policies, and evidence practices already exist; your project inherits them rather than paying to invent them.
We do not claim SOC 2 certification or compliance until an independent auditor's report exists for the system in question. We will always tell you precisely which of these controls apply to your deployment, in writing.
Questions, disclosures, or a security concern
Write to mthibideau@investhamiltoncounty.com. Security reports are read by a human, acknowledged, and tracked to resolution under our incident-response plan.