Compliance FAQ
What compliance certifications does AlphaGeo have?
We have achieved SOC 2 Type I and II certifications. We are also GDPR and CCPA-CCPR aligned.
How does AlphaGeo ensure regulatory compliance?
AlphaGeo ensures regulatory compliance through tailored processes and procedures aligned with security laws and standards applicable to its operations. It implements information security policies, conducts risk assessments, and monitors control effectiveness.
How does AlphaGeo handle incident response and data management?
AlphaGeo has established incident response plans, automated data backup policies, and a disaster recovery plan. It manages data retention through encryption, backup integrity checks, and compliance with data protection laws.
What is AlphaGeo’s approach to risk management?
AlphaGeo takes a systematic approach to risk management, involving risk identification, assessment of likelihood and impact, treatment plans, and reporting to leadership. It conducts vulnerability management and regularly reviews business processes for internal controls.
How does AlphaGeo adapt with the failover to a Disaster Recovery environment?
Our current data backup and recovery protocols are well-aligned with the requirement to failover to a Disaster Recovery environment within 1 week for a Tier 4 low criticality system. The use of our cloud provider’s automated and point-in-time backup features, combined with our daily backup frequency and stringent integrity checks, ensures that we can meet this requirement effectively and reliably.
How does AlphaGeo ensure data security?
AlphaGeo ensures data security through several measures:
Encryption of data at rest and in transit using industry-standard protocols.
Strict access controls and monitoring through AWS IAM policies.
Secure handling of user data in AWS RDS encrypted databases.
Regular security audits, vulnerability scans, and penetration testing.
Incident response procedures and employee training on security best practices.
Is there a physical security program in place, along with established offsite storage and visitor policy procedures?
No, AlphaGeo operates with a remote working model and does not maintain physical office spaces or provide company-supplied hardware.
Has your company suffered data loss or security breach within the last 3 years?
No, the company has not suffered any data loss or any security breach.
Last updated