Alert / Security
Security

Built on public data. Operated with care.

Alert is built from publicly available ecosystem signals and licensed data, and we run the platform with the controls a security-conscious buyer expects. Here is exactly where things stand, stated plainly.

How your workspace is protected

Every customer workspace is isolated at the database layer, not just in application code, so one account can never read another's watchlist, pipeline, or notes.

Encryption in transit and at rest

TLS for every connection; data encrypted at rest on our infrastructure provider.

Row-level tenant isolation

Postgres row-level security enforces workspace boundaries on every query the application makes.

We never hold your card

Payments run entirely on Stripe. Card numbers never touch Alert servers.

How the data is sourced

Signals derive from public app listings, public reviews, public storefronts, and licensed commercial datasets. Contact records are business contacts, and we honor removal requests.

Public and licensed sources

No scraping behind logins, no private data. If it is in Alert, it was public or licensed.

Deletion and removal requests

Merchants and individuals can request removal at any time and we action it.

Least-privilege operations

Staff tooling is role-gated and production access is limited to what operating the service requires.

We are an early-stage company and we say so: formal certifications such as SOC 2 are on our roadmap, not on our wall yet. If your security review needs specifics before then, write to security@alertcommerce.com and we will answer directly, engineer to engineer.