Security Overview

Security Overview

Security posture for tenant isolation, billing safety, readiness gates, auditability, and incident handling.

Controls in place

Alignyx Drive uses signed identity context, tenant-scoped service contracts, rate limits, CSRF protections, safe redirects, webhook signatures, and readiness endpoints that fail closed.

  • Stripe webhooks require raw-body signature verification and replay protection.
  • Postgres readiness checks require representative connection, committed migration state, RLS proof, backup policy evidence, and rollback planning before production approval.
  • Health, readiness, and dependency endpoints expose only safe status labels and blocker codes.
  • Claim and sign-in reference fields remain untrusted client input; the server validates references, one-time codes, tenant context, and paid status before opening protected workspace access.
  • Checkout requests reject client-supplied price, tenant, customer, redirect, and pre-payment dealership intake fields. Stripe session metadata records the server-selected plan and Terms version.

Incident handling

Severity rules prioritize security, privacy, tenant isolation, billing overcharge, and product availability. Each incident needs an owner until containment and resolution evidence are attached.

Limitations

This overview is not a certification report, audit opinion, or penetration-test attestation. Customer security questionnaires, formal audits, and signed security addenda should be handled through the support or contracting process.

Alignyx Drive™ does not claim SOC 2, ISO 27001, PCI DSS, HIPAA, GLBA, FCRA, or other formal certification unless separate written evidence is provided. Payment card entry is intended to occur through Stripe-hosted payment fields, not through Alignyx Drive forms.