Security

Our commitment to security

Security and the protection of customer and partner data are foundational to how we build and operate Alaka'i — not an afterthought. As we grow, we're aligning our internal controls with SOC 2 Trust Services Criteria. This page describes our approach today and how to reach us with concerns.

Access management

We apply role-based access controls and least-privilege principles across our client and company systems, so people only have access to the data and tools their role actually requires.

Data protection

Sensitive data is encrypted in transit, and at rest where applicable. We treat every byte of data our clients and partners entrust to us with the same care we'd want for our own.

Vendor oversight

We review the vendors and service providers who handle data on our behalf on an ongoing basis, and hold them to the same standards we hold ourselves.

Employee training

Our team completes ongoing security and privacy awareness training — good practices start with the people building and operating the platform.

Incident response

We maintain documented procedures for identifying, escalating, and responding to security incidents quickly, so issues get resolved and communicated without delay.

Reporting a security concern

If you believe you've found a security vulnerability or spotted suspicious activity involving Alaka'i, we want to hear about it — whether you're a customer, partner, vendor, or independent researcher. Include what you observed, where, and how to reproduce it, along with contact details so we can follow up. We acknowledge every report within one business day and handle it confidentially.

Security: security@alakai.io

How we communicate updates

We notify affected customers promptly if we identify an incident involving their data, and we share material updates to this page as our security program matures. For general privacy questions, reach out to our privacy team directly — for anything security-related, use the email below so it reaches the right people quickly.

Privacy: privacy@alakai.io

Responsible disclosure

We ask that anyone reporting a concern act in good faith: avoid accessing, modifying, or deleting data beyond what's needed to demonstrate the issue, avoid disrupting our services, and give us a reasonable opportunity to investigate before sharing it publicly. We will not pursue legal action against researchers who make a good-faith effort to follow this approach.

What to include in your report

When you reach out, please include as much of the following as you can:

  • A description of the issue and where you observed it — a URL, system, or process
  • Steps to reproduce the issue, if applicable
  • Any relevant screenshots, logs, or supporting details
  • Your contact information, so we can follow up with questions or updates