Trust & Security

Your deals are confidential. We keep them that way.

Your pipeline, your relationships, and your market knowledge are among the most sensitive assets your firm holds. Altrio protects them with the same enterprise-grade controls institutional investors demand: encryption, independent audits, and strict access governance.

  • SOC 2
  • GDPR
  • CCPA
  • 256-bit AES encryption
Security & Compliance

How we protect your data

Enterprise-grade security is table stakes in institutional dealmaking. These are the controls we operate at every layer of the platform — audited independently, year after year.

Secure cloud infrastructure

Altrio runs on Amazon Web Services, a cloud provider compliant with rigorous security standards including SOC 1/2/3, FISMA, and ISO 9001. Redundancy across data centers delivers high uptime and keeps your team working without disruption.

Independent security audits

We complete annual SOC 2 Type 2 assessments for the Security and Availability trust principles established by the AICPA, along with routine third-party penetration testing — so you can meet the requirements of the most stringent investors.

Encryption in transit and at rest

Data, documents, and other media are encrypted at rest using 256-bit AES. Everything transmitted between your browser and Altrio is encrypted in transit using Transport Layer Security (TLS).

Privacy and data compliance

You should never have to second-guess how your data is being used. Altrio complies with both GDPR and CCPA, and we are committed to transparency around our data practices. Read our Privacy Policy

Strong user authentication

Two-factor authentication is available to every user, and strong password policies are enforced on every account. Enterprise customers can sign in through their organization's single sign-on for tighter access control.

Granular controls and audit logs

Role-based permissions restrict who can view, edit, and export sensitive information. Automatic audit logging tracks every change in a central log, so you always know who did what, and when.

AI you can trust

Your data is never used for AI training

Nothing you put into Altrio is used to train AI models or shared with AI vendors. Your deal data is your competitive edge, and it works only for you.

Never used for training

No customer data is used to train AI models — ours or anyone else's. Your deals, documents, and communications stay out of every training set.

Never shared with AI vendors

We do not share customer data with third-party AI vendors. Everything you put into Altrio stays within Altrio's secure infrastructure.

Governed by your permissions

AI features operate within each user's existing permissions, and every action is audit-logged. Assistants see exactly what the user sees — nothing more.

Security FAQ

Answers for your security review

Is Altrio SOC 2 compliant?
Yes. Altrio completes SOC 2 Type 2 assessments annually, covering the AICPA's Security and Availability trust principles, and undergoes routine third-party penetration testing. Contact us to request our latest report for your vendor review.
Is my data used to train AI models?
No. Customer data is never used to train AI models — ours or any third party's — and it is never shared with AI vendors. Altrio's AI features operate entirely within our secure infrastructure and within each user's existing permissions.
Where is my data hosted?
Altrio is hosted on Amazon Web Services, a cloud provider compliant with security standards including SOC 1/2/3, FISMA, and ISO 9001. Redundancy across data centers provides high availability.
How is my data encrypted?
All data, documents, and media are encrypted at rest with 256-bit AES, and all traffic between your browser and Altrio is encrypted in transit with TLS.
Does Altrio support single sign-on?
Yes. Enterprise customers can authenticate through their organization's single sign-on. Two-factor authentication and enforced password policies are available for every account.
Who at my firm can access sensitive deal data?
That's up to you. Role-based permissions let you control who can view, edit, and export information, and automatic audit logging records every change in a central log.