Aliezia

Security at Aliezia

Clear safeguards. No inflated language.

Aliezia is built around authenticated access, private document handling, server-side verification, and database-level authorization. This page distinguishes implemented controls from planned capabilities.

Implemented safeguards

Security controls tied to actual product behavior.

The statements below reflect implemented architecture or infrastructure-provider capabilities. They are not a certification, audit opinion, penetration-test result, or uptime guarantee.

Authentication

Supabase Auth verifies user identity and manages secure session cookies for authenticated product routes.

Authorization

PostgreSQL row-level security and server-side checks restrict access based on authenticated users and organization relationships.

Private documents

Confidential documents use private storage. Approved deal-room downloads use signed URLs that expire after 15 minutes.

Webhook integrity

DocuSign events are validated with configured HMAC keys and recorded with idempotency controls before status changes are applied.

Transport and infrastructure encryption

HTTPS protects data in transit. Encryption at rest is provided by the selected hosting, database, and storage infrastructure.

Data boundaries

CRM, NDA, and deal-room records use relational constraints and row-level policies instead of trusting browser-supplied ownership state.

Secrets

Service-role, billing, email, and signature-provider secrets remain server-side and are validated through environment configuration.

Provider transparency

The Subprocessors page identifies the infrastructure and transaction providers used or conditionally enabled by the product.

Customer controls

Access and document delivery stay intentionally bounded.

Users control authenticated workspace access. Broker-owned NDA templates remain private and immutable by version after upload. Deal-room materials are not exposed through public storage.

Current control path

  1. 01Authenticate the account or signer
  2. 02Verify workspace, property, or deal scope
  3. 03Apply row-level or server-side authorization
  4. 04Issue only the minimum access required
  5. 05Expire temporary document access automatically

Planned or readiness-stage

Not represented as operational today

  • Organization SSO configuration
  • Customer-facing audit-log experience
  • Provider-supported MFA enablement interface
  • Formal responsible-disclosure program
  • Documented business-continuity and incident-response publication

No certification claim

Evidence should precede the badge.

Aliezia does not claim SOC 2, ISO 27001, HIPAA, GDPR certification, CCPA certification, a specific uptime service level, or completed independent penetration testing on this page. Any future claim must be supported and documented before publication.

Security questions: security@aliezia.com

A clearer way to work

Bring every relationship and opportunity into focus.

Start a 14-day trial without a credit card, or walk through the Aliezia workflow with our team.