TRUST & SECURITY
Trust & Security at Alpha Recon.
ARops handles principal risk profiles, human risk assessments, and client operational data. Here’s how that’s actually collected, verified, and protected, in plain terms, not legal boilerplate. This page covers the practical questions a security director or vendor risk reviewer actually asks, not a checklist of certifications, since we’d rather state what’s true than imply something that isn’t.
DATA & AI SECURITY
Client data doesn’t train public models.
AI accelerates how signal gets surfaced. It doesn’t get access to client data on the same terms a public tool would.
No public LLM exposure
Client data is never pushed into public large language models. Many AI tools quietly expand an organization’s attack surface, ARops is built to shrink it instead.
Tenant isolation
Client data is isolated by account. There’s no cross-contamination between clients, and nothing from one engagement trains or influences another.
Encrypted at rest and in transit
Data is encrypted with AES-256 at rest and TLS 1.2 or higher in transit, standard, verifiable encryption practice, not a marketing claim.
No training contamination
Client-specific data isn’t used to train shared models. What’s collected for your engagement stays scoped to your engagement.
HOW COLLECTION WORKS
OSINT-based, human-verified, nothing covert.
Alpha Recon does not collect data through covert surveillance, deceptive means, or unauthorized access, a commitment stated plainly in the Privacy Policy and reflected in how every report is actually built.
Open-source collection
Findings are built from surface, deep, and dark web sources, social media, public records, and geospatial imagery, supplemented by partner feeds for digital attack surface visibility. No classified or illegal sources.
Asset-centric methodology
Threat factors are mapped to the attack surface that actually matters: principals, residences, routes, venues, and digital exposure. Every output ties a signal to an asset to a recommended protective action.
Human verification, every time
AI-assisted monitoring surfaces and organizes signal at scale. Nothing reaches your team until a human analyst has reviewed and verified it, speed doesn’t come at the cost of accuracy.
Confidence tagging
Every finding carries a confidence tag, Confirmed, Assessed, Probable, or OSINT Gap, so you know exactly how solid each claim is instead of everything reading as equally certain.
CONFIDENTIALITY & ACCESS
Your reporting stays with your assigned team.
Access to client data and reporting is limited by design, not just by policy.
Assigned-team access only
Only the analyst team assigned to your account can see your reporting. Nobody outside that team has access, and it’s handled under confidentiality throughout.
Personal data is never sold
Alpha Recon does not sell personal data. That’s a direct commitment in the published Privacy Policy, not a qualified statement with exceptions buried in it.
Finished reports belong to you
Deliverables produced for your engagement are yours to use, share, and file as needed. The underlying methodology, sourcing approach, and platform remain Alpha Recon’s, standard for how a services relationship like this works, the same way a law firm’s work product is yours while their internal processes remain theirs.
Reasonable safeguards, honestly stated
Alpha Recon maintains reasonable administrative, technical, and organizational measures to protect data. No system is guaranteed to be completely secure, and that’s stated plainly rather than oversold.
Have a specific security question?
Vendor security reviews, data handling questions tied to a specific engagement, or anything not covered above, talk directly with the team rather than trying to piece it together from this page alone.