Security
Built to hold institutional records
Alethia keeps corporate registers, ownership and documents for regulated firms. Data is stored and processed in the UK and Europe, isolated per customer, and encrypted throughout.
Data stays in the UK and Europe
Your workspace records — entities, people, ownership, documents and audit history — are stored in the United Kingdom (London region). Application servers run in Europe too.
Encrypted in transit and at rest
Every connection is TLS-encrypted, and stored data is encrypted at rest. Sensitive secrets such as two-factor seeds carry an additional layer of authenticated AES-256 encryption.
Every workspace is isolated
One customer can never read another's data. Isolation is enforced in the database itself by security rules, not just in application code — and that boundary is covered by an automated test suite.
Strong authentication and access
Multi-factor authentication, single sign-on and SCIM provisioning, with role-based access inside each workspace. Server requests are verified on every call and revoked sessions lose access immediately.
Audited and accountable
Material changes to registers, appointments and ownership are recorded to an audit trail, so there is always a defensible record of who changed what and when.
AI that only ever proposes
Our AI features draft and extract for a human to approve — they never write to your records on their own. Your workspace data is not used to train third-party models or sent to translation tooling.
Where your data lives
Customer workspace content is stored in Google Cloud’s London (europe-west2)region, and the application’s servers run in Europe. For institutions that need their corporate and beneficial-ownership records to remain in the UK and EU, that is the default — not an add-on.
A small, named set of sub-processors supports the service — for example payment processing and transactional email. Where any of them processes limited personal data outside the UK or EEA, it is under standard data-protection safeguards. The full list and the legal detail are in our Privacy Policy.
Encryption
Data is encrypted in transit with TLS and encrypted at rest by the underlying platform. The public site and the application are served over HTTPS only, with HSTS and a strict set of security headers. Where we hold especially sensitive values, such as the seed behind a user’s authenticator app, we add a further layer of authenticated AES-256-GCM encryption so that the stored value is useless without the key.
Tenant isolation and access control
Each customer works inside their own workspace. Access to workspace content is governed by database security rules that check membership and role on every read and write, so isolation does not depend on application code alone. Inside a workspace, roles determine what each member can see and do.
Sign-in supports multi-factor authentication and enterprise single sign-on, and larger customers can provision and deprovision users automatically over SCIM. Server-side requests verify the caller’s identity on every call and honour session revocation, so removing someone’s access takes effect immediately.
Governance, audit and AI safety
Alethia keeps an audit trail of material changes to the register — appointments, ownership, statutory data and documents — so there is always an accountable record. Maker-checker approval workflows are available for teams that need a second pair of eyes before a change is committed.
Our AI features are deliberately proposal-only: they search, extract and draft for a person to review and approve, and never alter your records unattended. Tenant-entered data is never sent to translation tooling and is not used to train third-party models.
Compliance and questions
We process personal data in line with UK and EU data-protection law. Customers can request a data-processing agreement, and enquiries — including security questionnaires and details of our sub-processors — are welcome ahead of a purchase.
Reviewing Alethia for your firm?
We are happy to walk your security and IT teams through data residency, access control and our sub-processors, and to complete a security questionnaire.