Skip to main content
Start free trial
Security & Compliance

Security worth
showing IT.

Encryption, isolation, audit logs. Every send logged. You can pause Alfred or require approval anytime.

Encrypted end-to-endPer-org isolationUS-hostedApproval queueFull audit trailSecure infrastructure

How Alfred protects your data

Six commitments
that aren’t theater.

We’re not going to pretend we’re Fort Knox. We’re an early-stage product. But here’s what we actually do — written without compliance buzzwords.

Managed Postgres hosting

Postgres on AWS US-East, managed by Supabase (SOC 2 Type 2 audited). Encrypted at rest and in transit.

Encrypted end-to-end

TLS 1.2+ in transit. AES-256 at rest. No exceptions.

Per-org data isolation

Postgres row-level security. Other businesses cannot see your data. Period.

You stay in control

Review-before-send is on by default — read every message, edit it, then approve. Pause Alfred anytime. Every send, and every send Alfred held, is logged with the reason.

You own your data

Export everything as CSV any time. Delete your account and we purge in 30 days.

Audit-ready logging

Every send, approval, and login logged for 12 months. Exportable on request.

An honest note

We’re an early-stage company. We don’t have SOC 2 Type II yet (it’s on the 2026 roadmap). We don’t have ISO 27001. We can’t honestly claim a 99.99% SLA — we’re building toward 99.9%.

What we do have: encryption at rest and in transit, per-org data isolation enforced at the database level, a full audit trail, and an approval queue that means nothing autonomous goes out without you tapping approve.

If your compliance team needs more, email hello@alfred-intelligence.com and we’ll send our security posture documentation under NDA, walk through your specific requirements, and tell you honestly whether we’re ready for your environment.

Frequently asked

Specifics, not slogans.

Alfred runs on infrastructure that can be brought under HIPAA — our database provider offers a Business Associate Agreement on its Team plan with the HIPAA add-on, which we enable before any practice onboards real patient data, alongside the BAA we sign with you. Messages are PHI-safe by enforcement, not just by convention: for a healthcare practice, Alfred blocks any send on a channel no BAA can cover, and holds any message whose copy reads as clinical detail rather than delivering it. Every hold is logged with its reason. Email hello@alfred-intelligence.com to request our BAA.

The primary database is managed Postgres on AWS, hosted by Supabase. Backups are encrypted. Point-in-time restore is not enabled on the current plan, and we will say so plainly rather than imply a recovery window we do not have. Ask us where your data is hosted and we will tell you the exact region.

Production database access is limited to two named engineers under signed confidentiality. We do not browse practice data for fun, never use real patient messaging in marketing, and never train models on your data without explicit opt-in.

We purge your contacts, message history, and journey data within 30 days. Audit logs are kept for 12 months for compliance, then permanently deleted. You can request immediate deletion of all data at any time.

Not yet — SOC 2 Type II is on our 2026 roadmap. If your organization requires SOC 2 before contract, contact us. We can share our full security posture documentation under NDA and walk through your specific requirements.

You decide how much Alfred sends on his own. Approval gates are available on every journey — switch one on and every draft waits in your inbox with the recipient, content, trigger, and timing before you tap approve. Either way the guardrails always apply: quiet hours, per-patient frequency caps, permanent unsubscribes, anomaly detection, and one-click pause.

Multi-factor authentication is available on every plan. Suspicious login locations trigger alerts. Failed-attempt rate limiting blocks brute-force attacks. We recommend enabling MFA on all owner-tier accounts.

We run on managed Postgres on AWS with encryption at rest and in transit, per-org data isolation, and a full audit trail. We don't currently hold SOC 2 or ISO 27001 certifications — that's our honest answer. If your compliance team needs specifics, email hello@alfred-intelligence.com and we'll walk through it.

Trust is the product.
Try Alfred risk-free.

14-day free trial. No card. No pressure. If we’re not the right fit for your compliance posture, we’ll tell you ourselves.