Alert is built from publicly available ecosystem signals and licensed data, and we run the platform with the controls a security-conscious buyer expects. Here is exactly where things stand, stated plainly.
Every customer workspace is isolated at the database layer, not just in application code, so one account can never read another's watchlist, pipeline, or notes.
TLS for every connection; data encrypted at rest on our infrastructure provider.
Postgres row-level security enforces workspace boundaries on every query the application makes.
Payments run entirely on Stripe. Card numbers never touch Alert servers.
Signals derive from public app listings, public reviews, public storefronts, and licensed commercial datasets. Contact records are business contacts, and we honor removal requests.
No scraping behind logins, no private data. If it is in Alert, it was public or licensed.
Merchants and individuals can request removal at any time and we action it.
Staff tooling is role-gated and production access is limited to what operating the service requires.
We are an early-stage company and we say so: formal certifications such as SOC 2 are on our roadmap, not on our wall yet. If your security review needs specifics before then, write to security@alertcommerce.com and we will answer directly, engineer to engineer.