Trust Center

Procurement-grade control for the operating system of digital labor.

Alabobai keeps trust conservative and explicit: no unearned certifications, no vague claims, no hidden vendor story. This page holds the evidence, response expectations, subprocessors, and procurement paths in one place.

No unearned certifications. Evidence available on request.

Procurement snapshot
Status locked
Certification posture
In progress

SOC 2 readiness is active; no complete certification is claimed.

Response window
24h business days

Security inquiries are acknowledged within one business day.

DPA path
/dpa

Request intake, review, redlines, and final signature are documented.

Contacts
security + legal

Procurement and security contacts are available in one place.

Clear boundaries, verifiable commitments, and procurement-ready proof.

This page is intentionally conservative. It exists to help legal, security, procurement, and operators review the platform without hunting across multiple pages for basic answers.

Evidence first

We do not claim certifications, attestations, or controls we do not have. Status is stated plainly.

Procurement ready

Security review, DPA flow, subprocessors, and contact paths live on one page for faster evaluation.

Least privilege

Subprocessors and infrastructure exist to operate the platform, not to widen the data surface by default.

Clear response windows

Business-day acknowledgement and incident update expectations are written as operating policy, not marketing copy.

Certification status

Current posture, stated without exaggeration.

ProgramStatusNotes
External certificationsNone issuedWe do not represent any certification, attestation, or audit report as complete unless it is complete.
SOC 2 Type IIIn progressControl mapping and audit preparation are in progress. No report has been issued yet.
ISO/IEC 27001PlannedPlanned after SOC 2 readiness milestones are completed.
ISO/IEC 27701PlannedPlanned as an extension to privacy governance after core ISMS maturity.

DPA request flow

One path from intake to signature.

  1. Submit the request at /dpa or email legal@alabobai.com.
  2. We confirm intake within 1 business day and route to legal/security.
  3. We provide the current DPA template and subprocessors list for review.
  4. Redlines are reviewed with enterprise stakeholders and resolved in writing.
  5. Final signature can be completed before production data onboarding.

Security contact and incident policy

Operational commitments written plainly.

  • Primary channel: security@alabobai.com
  • Initial acknowledgement SLA: within 24 hours on business days
  • High-severity security reports: triage begins immediately after validation
  • Status updates: at least every 24 hours for active high-severity incidents
  • Confirmed incidents affecting customer data are disclosed without undue delay.
  • Target initial customer notice window: within 72 hours of confirmation when legally required.
  • Disclosure includes impact scope, affected data classes, mitigation, and next updates.
  • Post-incident review and corrective actions are documented and tracked to completion.

Subprocessors

Vendors supporting the platform stack.

VendorPurposeRegion
OpenAILLM inference for enabled cloud AI workflowsUS (provider-managed)
Google Cloud PlatformApplication hosting and infrastructure servicesUS primary region
SupabaseManaged Postgres, auth support, and storageUS primary region
UpstashRate limiting and cache servicesUS (provider-managed)