Security · Alloy

Alloy Logo

The security of your data is our #1 priority.

Last updated: 13 July 2026

Security, reliability, privacy, and compliance are at the heart of everything we do at Alloy. Safeguarding your information isn't just a part of our daily routine; every facet of our engineering and operations have been vetted to ensure the protection of your data.

We utilize industry-standard cloud infrastructure vendors to provide the Alloy service, and also implement additional processes and controls. Our posture is informed by industry experts, and we also bring deep expertise in operating secure software from our time at some of the world's best and most advanced software companies.

Backups occur on a daily basis to a separate region, are persisted, and regularly tested for recovery. All data is encrypted with industry-standard encryption at rest (AES-256) and in transit (HTTPS/TLS). We also conduct static code analysis, external penetration tests, third-party vulnerability scanning and audits, and also implement many other industry-standard Cloud security techniques.

Explore our Security & Data Protection Center, where you'll find detailed information on our controls along with supporting documentation. If you have any questions, please don't hesitate to contact us at security@alloy.app.

Current security and compliance documentation

Alloy maintains an active security program covering product, infrastructure, and vendor controls. Alloy's SOC 2 Type II audit is in progress, with estimated completion in Q3 2026. For audit-period details, current status, and any available report-access process, contact us at security@alloy.app.

  • SOC 2 Type II: In progress; estimated completion Q3 2026
  • Audit logs: Upcoming
  • Data residency: Upcoming

Frequently asked questions

What data does Alloy store?

When provisioning a user account, we store your full name, email address, and (optionally) a profile photo.

While using Alloy, users may import, connect, capture, upload, enter, and generate content depending on the features and integrations they enable. This can include code repository data, captured product pages, session prompts and instructions, uploaded files, integration content from connected tools, generated code, prototypes, assets, comments, collaboration activity, and related metadata. To best understand the data your organization expects to store in Alloy, we recommend talking to your workspace admins and the individuals who will use Alloy.

Where does Alloy store data?

We store data in Amazon Web Services (AWS) data centers in the United States. Your data will be stored in us-west-2 (Oregon) with database replication to us-west-1 (N. California) for backups.

Is Alloy SOC 2 compliant?

Not yet. Alloy's SOC 2 Type II audit is in progress, with estimated completion in Q3 2026. Contact security@alloy.app or your Alloy sales contact for audit-period details, current status, and any report-access requirements once a report is available.

Do you fill out security assessments?

Yes. We are happy to fill out security assessments on request – please contact us.

Is external penetration testing performed, and has the platform been reviewed by an independent third-party?

External penetration testing is part of Alloy's security program. Contact security@alloy.app for the current most recent test date, scope, and any available summary or remediation materials.

Is your data encrypted?

Yes, Alloy provides industry-standard encryption at rest (AES-256) and in transit (HTTPS/TLS 1.2 and 1.3).

Do you provide SAML, Single Sign-On (SSO), or advanced authentication controls?

Yes. We provide SSO on our Enterprise plan, compatible with most IdPs with support for both SAML and OIDC protocols. Please contact us with your specific requirements for more information.

Do you have a list of subprocessors?

Yes, an updated list of data subprocessors is available by request. Contact us at support@alloy.app and we'll be happy to help.

How can I report security issues and vulnerabilities?

Alloy takes security issues and vulnerabilities very seriously. If you believe you have found a security issue, please contact us at security@alloy.app and we'll review it as soon as possible.

Does Alloy have a bug bounty / responsible disclosure program?

Yes. Alloy has a private Bug Bounty program that rewards researchers for finding and reporting security vulnerabilities. For more information, or to report a vulnerability, please visit our Responsible Disclosure page or reach out to us at security@alloy.app.

How can I access, transfer, or delete my data?

Contact us at support@alloy.app and we'll be happy to help.