Legal
How we protect Allocatin accounts, tenants, and professional data. This page is our public security summary, not a certification.
Changes go through review and automated checks. Secrets are kept out of the client. Demo mode is isolated from production credentials. We do not ask the mobile apps for camera, photos, or Face ID.
Hosting, auth, billing, and AI inference are provided by the companies on Subprocessors. We review their security documentation as part of onboarding and periodically after that.
Unauthorized tenant data is not sent to models. Generation that faces a counterparty is designed to stay evidence-backed, with a human approval step before send where that feature exists. See AI transparency.
If we confirm a personal-data breach that affects you, we will notify you and, where required, regulators without undue delay. Email suspected issues immediately to security@allocatin.com. Please include the account email, time window, and any indicators of compromise. Do not attach live credentials.
We are not claiming a current SOC 2 or ISO 27001 report on this page. Our internal roadmap is policies and vendor reviews first, then independent testing and SOC 2 readiness, then Type I / Type II as the business matures. Customers can request the latest questionnaire at security@allocatin.com.