Skip to content
Value Alpha

Protecting your data is core to how Value Alpha is built

Your financial statements are among the most sensitive documents you own. From how data is stored, to who can reach it, to how it moves, every layer of Value Alpha is designed to keep it private and under your control.

Your data stays yours
  • You own your data. We do not sell it or share it with third parties for their own use.
  • No training on your data. AI providers process your inputs on business API tiers that are contractually barred from training on them.
  • You stay in control. Export a copy of your data, or delete your account and its data yourself, any time from settings.
Access, isolated at the database
  • Row-level isolation. Your companies, valuations, statements, and uploads are readable only by you and the people you explicitly share them with.
  • Private storage. Uploads live in private, per-user storage, with format and size limits.
  • Controlled sharing. Share links are revocable tokens you can set to expire; shared data rooms add email verification, a named allowlist, and passcodes.
  • Access monitoring. We log access to your reports and alert automatically on unusual patterns.
Encrypted in transit and at rest
  • Encryption everywhere. Modern TLS in transit, and encryption at rest on our infrastructure providers.
  • Network protection. Served behind Cloudflare, with DDoS protection and a global content network.
  • Hardening. A strict content security policy, and rate limits across the application and database.
Payments never touch our servers
  • Stripe-hosted checkout. Your card details go directly to Stripe and are never seen or stored by Value Alpha.
  • Card security. Stripe is certified to PCI-DSS Level 1, the highest level in the payment card industry.
AI, with no training on your data
  • Established providers. We use established AI providers for valuation narratives, document parsing, and chat.
  • No training on your content. Providers run on API tiers that do not train on your data, and we do not train our own models on it.
  • Accountable usage. We keep a record of AI usage so we can account for how the feature is used.
Your privacy rights
  • Recognized rights. We support GDPR and CCPA rights, including access, export, correction, and deletion.
  • Self-serve controls. One-click data export and account deletion are available in your settings.
  • Documented terms. A published retention schedule, and a Data Processing Addendum on request for institutional customers. See our Privacy Policy and Terms.
Infrastructure and compliance

We build on a small number of established infrastructure providers, each responsible for security within its own platform. Our core providers maintain recognized, independently audited standards such as SOC 2 Type II, ISO 27001, and PCI-DSS, and every provider is bound by a written data-processing agreement.

Our full, current list of sub-processors is available on request. Email [email protected] and we will share it.

Reporting a security issue

If you believe you have found a security vulnerability, we want to hear from you. Email [email protected] with the details and steps to reproduce. We will acknowledge your report, investigate, and keep you informed.

Please give us a reasonable window to remediate before any public disclosure, and do not access or modify data that is not yours while testing.

Value Alpha is a product of Felpel Ventures LLC. This page describes our practices as they stand today and is provided for information. It is not a contractual warranty; contractual commitments live in our Terms of Service and Data Processing Addendum.