Alphaloops Trust Center

Trust center

AlphaLoops publishes a security page at https://runalphaloops.com/security and operates a Vanta-hosted Trust Center at https://trust.runalphaloops.com/ (linked from the site footer). The Trust Center returned HTTP 200 but is fully client-rendered — no certification names, control list, or document index are present in the served HTML, and the Vanta trust-page API paths probed anonymously return the SPA shell rather than JSON. The certifications below are therefore read from the PUBLIC SECURITY PAGE, not from the Trust Center itself.

AlphaLoops FMCSA Carrier Data API maintains a public trust center documenting SOC 2 Type II, ISO 27001, NIST Cybersecurity Framework, and COBIT compliance.

fmcsa apisafer web apidot lookupcarrier datafreighttruckingmotor carrierfleet intelligencesales intelligencemcp servercontact enrichmentriskfraud
Trust center: https://trust.runalphaloops.com/

Certifications & Compliance

SOC 2 Type IIISO 27001NIST Cybersecurity FrameworkCOBIT

Source

Trust Center

Raw ↑
generated: '2026-08-11'
method: searched
probe: true
source: https://runalphaloops.com/security
url: https://trust.runalphaloops.com/
description: >-
  AlphaLoops publishes a security page at https://runalphaloops.com/security and operates a
  Vanta-hosted Trust Center at https://trust.runalphaloops.com/ (linked from the site footer).
  The Trust Center returned HTTP 200 but is fully client-rendered — no certification names,
  control list, or document index are present in the served HTML, and the Vanta trust-page API
  paths probed anonymously return the SPA shell rather than JSON. The certifications below are
  therefore read from the PUBLIC SECURITY PAGE, not from the Trust Center itself.

# IMPORTANT — these are the claims as WORDED by the provider. AlphaLoops describes itself as
# "aligned with" ISO 27001 and built on "SOC 2 certified infrastructure". That is a posture
# statement about controls and about its cloud vendors; it is NOT an assertion that AlphaLoops
# itself holds a SOC 2 or ISO 27001 certificate, and no audit report, certificate number, or
# auditor is named on any public page. Recorded verbatim so the distinction is not lost.
certifications:
  - name: SOC 2 Type II
    claim: infrastructure
    status: claimed-alignment
    verbatim: 'SOC 2 Type II infrastructure'
    certificate_published: false
    note: >-
      Stated as the compliance posture of the underlying infrastructure. No SOC 2 report,
      certificate, or auditor is named on a public page, and the Trust Center that would
      normally host the report is not machine-readable.
  - name: ISO 27001
    claim: aligned
    status: claimed-alignment
    verbatim: 'ISO 27001 aligned controls'
    certificate_published: false
    note: Described as "aligned with" / "aligned controls" — not stated as a held certification.
  - name: NIST Cybersecurity Framework
    claim: aligned
    status: claimed-alignment
    verbatim: 'NIST Cybersecurity Framework'
    certificate_published: false
  - name: COBIT
    claim: aligned
    status: claimed-alignment
    verbatim: 'COBIT governance domains'
    certificate_published: false

# Privacy regimes named on the pricing page against the contact-data add-on.
privacy_regimes:
  - name: GDPR
    verbatim: 'GDPR and CCPA compliant'
    source: https://runalphaloops.com/pricing
  - name: CCPA
    verbatim: 'GDPR and CCPA compliant'
    source: https://runalphaloops.com/pricing

security_program:
  penetration_testing:
    cadence: weekly
    provider: Intruder.io
    methodology: OWASP
    coverage:
      - Web applications & APIs
      - Infrastructure endpoints
      - OWASP Top 10 vulnerabilities
      - Emerging threat detection
    remediation_sla:
      critical: 7 days
      high: 14 days
      medium: 30 days
      low: 90 days
  encryption:
    in_transit: TLS 1.3
    at_rest: AES-256
    notes:
      - Perfect forward secrecy
      - Encrypted database connections
  authentication:
    - 100% MFA enforcement across all systems
    - FIDO2/WebAuthn hardware key support
    - Phishing-resistant authentication methods
    - Rate limiting and account lockout protection
  access_control:
    - Row-level security (RLS) for data isolation
    - Least privilege access model
    - Quarterly access reviews
    - 24-hour deprovisioning SLA
  infrastructure:
    - DDoS protection via Cloudflare
    - Web Application Firewall (WAF)
    - Network segmentation
    - API rate limiting
  monitoring:
    - Real-time security event logging
    - Anomaly detection systems
    - Automated threat response
    - Comprehensive audit trails
  data_minimization: >-
    "Only process DOT numbers - no sensitive personal or financial data" — as published. Note this
    sits in tension with the product's own contact-enrichment surface, which returns work email,
    personal emails, phone numbers and employment history for named individuals
    (see openapi EnrichedContact schema and the contact-credits add-on on the pricing page).

evidence:
  - url: https://runalphaloops.com/security
    http_status: 200
    note: Server-rendered; all certification and control claims above read from this page.
  - url: https://trust.runalphaloops.com/
    http_status: 200
    note: Vanta-hosted Trust Center; JS-rendered, no certifications present in served HTML.
  - url: https://runalphaloops.com/pricing
    http_status: 200
    note: GDPR/CCPA claim against the contact-data add-on.