Where your clients’ data lives, and who can reach it.
You are putting other people’s financial records into someone else’s software. This page is the straight answer about what happens to them — written for the person who has to defend the decision to their client.
The short version
- Not SOC 2 certified.
- Stated plainly rather than buried. The controls below follow what those frameworks expect, and the infrastructure underneath Alpyne is independently audited — but Alpyne itself does not hold the certification.
- AI and ledger writes are separate switches, set per client.
- Run one client with both on and the next with both off. Nothing is account-wide.
- Nothing posts to your books without a person approving it.
- AI suggestions arrive as proposals. Every applied write is logged with what changed, when, and who approved it.
- Your data is not used to train AI models.
- AI runs on Anthropic’s commercial Claude API, whose commercial terms exclude customer data from training. No other AI vendor receives client data.
- One person has production access.
- Bryan McGowan, who wrote the system. Not a team, not a rotating on-call roster, and not an offshore support desk.
Hosting and infrastructure
Alpyne runs entirely on managed cloud platforms in the United States. We do not operate our own servers or data centers. Each provider maintains its own independent security certifications and audits.
| Component | Provider | Notes |
|---|---|---|
| Application servers | Render | Managed platform, US East (Virginia) |
| Primary database | Render managed PostgreSQL | US East (Virginia). Direct access limited to an IP allowlist |
| Background processing | Render — Sidekiq workers, managed Redis | Connections to Redis use TLS |
| File storage | Google Cloud Storage | Documents and exports you upload or generate |
| AI processing | Anthropic (Claude API) | Commercial API. See AI features below |
Data protection
All traffic to Alpyne is encrypted in transit, and data is stored on infrastructure that encrypts at rest.
- In transit
- Every connection is forced over HTTPS with HTTP Strict Transport Security enabled. Unencrypted requests are redirected.
- At rest
- Database and file storage run on managed providers that encrypt at rest. Selected sensitive fields — connection tokens, payment API keys, MFA secrets — are encrypted again at the application layer.
- Passwords
- Never stored in plain text. Hashed with bcrypt, and changing a password signs out every other session.
- Secrets
- API keys and encryption keys live in the hosting platform’s environment configuration, never in source code.
- Logs
- Passwords, tokens, keys and similar fields are filtered out of application request logs.
- Browser protections
- Session cookies are secure and HTTP-only and expire after 24 hours. Security headers block clickjacking, content sniffing and cross-site framing. Cross-origin requests are accepted only from Alpyne’s own domains.
Access control
A user can see a client’s data only if their firm has given them access to that client. The server checks this on every request.
- Client isolation
- Every request names the client being viewed, and the server checks that the signed-in user is authorized for it. If they are not, the request is rejected.
- Multi-factor authentication
- Users can turn on authenticator-app MFA with one-time backup codes. Firms can require it for administrators or for everyone.
- Brute-force protection
- Sign-in and registration attempts are rate-limited per IP address. Automated and malicious traffic patterns are blocked.
- Revoking access
- Firm administrators can remove a user or unassign a client at any time. Access ends right away.
| Role | Can access |
|---|---|
| Firm administrator | All active clients of their firm, plus firm settings |
| Firm user | Only the clients they are assigned to |
| Client user | Only their own company |
Connections to your financial systems
Alpyne connects through each provider’s own authorization flow. We never see or store your passwords for those systems.
- OAuth authorization
- QuickBooks Online, Xero, HubSpot, Salesforce, Shopify, Google and others connect through their own sign-in and consent screens. Alpyne receives a scoped access token you can revoke at any time, from Alpyne or from the provider.
- Bank data through Plaid
- Bank and card connections use Plaid, and Alpyne uses it only to read transactions, balances and asset reports. It does not use Plaid products that move money.
- Accounting write access
- QuickBooks and Xero connections include write permission. Alpyne writes to your books only when an authorized user starts an action — posting a journal entry, reclassifying transactions — or when a firm explicitly turns on an automation, such as syncing Stripe or Shopify activity into QuickBooks.
- Disconnecting
- When a connection is removed, or a client is deleted from Alpyne, its tokens and synced data are removed.
AI features
Alpyne’s AI features run on Anthropic’s commercial Claude API. Under Anthropic’s commercial terms, customer data sent through the API is not used to train its models.
- Scoped to one client
- The AI assistant works inside the same access checks as the rest of Alpyne. It can see only the client data the signed-in user is already authorized to view.
- Isolated analytics
- For AI-generated data queries, each company’s data sits in its own database schema. Queries are validated against a list of allowed tables, run read-only, and have strict time and row limits.
- Human review
- AI-suggested changes — adjustments, allocations, reclassifications — are shown as proposals. Nothing is applied until a person reviews and approves it.
- No other AI providers
- Client data is not sent to any other AI vendor.
Operational practices
Changes are version-controlled and checked before release, and production access is restricted to one person.
- Backups
- The managed database is backed up automatically by the hosting provider and can be restored to a recent point in time.
- Monitoring
- Application performance and errors are monitored continuously. Rate limits and blocklists protect the service from abusive traffic.
- Change management
- All code changes go through version control. Automated checks for type safety, linting and code style run before changes are released.
- Internal access
- Bryan McGowan is the only person with access to production systems. Direct database access is limited to approved IP addresses. Client data is accessed only when needed for support or to fix a problem.
- Data deletion
- When a firm removes a client, Alpyne deletes that client’s synced data and integration connections.
- Incident response
- If we learn of a security incident affecting your data, we investigate right away and notify affected firms promptly.
Questions people actually ask
- Is Alpyne SOC 2 certified?
- No. Alpyne is not SOC 2 certified, and we will not imply otherwise. The controls described on this page follow the principles those frameworks expect — access control, encryption, change management, vendor oversight — and the infrastructure providers underneath Alpyne are independently audited against them. If SOC 2 certification is a hard requirement for your clients, tell us; it is on the roadmap and knowing it blocks a deal moves it up.
- Can I turn off the AI features?
- Yes, per client. AI features and ledger write access are two separate switches, each set individually for every client. A firm can run one client with both on and the next with both off, or allow AI analysis while blocking any write to the books. Nothing is all-or-nothing at the account level.
- Does Alpyne write to my clients’ books?
- Only when someone tells it to, and only where write access is turned on for that client. AI-suggested changes appear as proposals that a person reviews and approves before anything posts. Every write is recorded with what changed, when, and who approved it.
- Where is my data stored?
- In the United States. Application servers and the primary database run on Render in US East (Virginia); files are in Google Cloud Storage. Alpyne does not operate its own servers or data centers.
- Is my data used to train AI models?
- No. AI features run on Anthropic’s commercial Claude API, and under Anthropic’s commercial terms customer data sent through the API is not used to train its models. Client data is not sent to any other AI vendor.
- Can you complete our security questionnaire?
- Yes. Send it to bryan@getalpyne.com and it comes back from the person who wrote the system, not a sales engineer reading a document.
Send the questionnaire.
If your firm or your client has specific requirements, a questionnaire, or a question this page does not answer, it comes back from the person who built the system.
bryan@getalpyne.com