Security at Alfacotex.
Last updated: June 1, 2026
We build a forensics tool. Security is not a feature we add on top. It is the foundation everything else is built on.
Encryption in transit
All data transmitted between your device and our servers is encrypted using TLS 1.3. API endpoints enforce HTTPS only.
Encryption at rest
Scan reports and account data are encrypted at rest using AES-256. Encryption keys are managed through a dedicated key management service and rotated regularly.
Local-first scanning
The Alfacotex agent performs forensic collection and initial analysis locally on your device. Raw disk images and memory dumps never leave your machine. Only structured results and the AI-generated report are transmitted to our servers.
Access controls
Internal access to production systems follows the principle of least privilege. All access requires multi-factor authentication and is logged for audit purposes.
Infrastructure
Our servers are hosted on dedicated infrastructure with full-disk encryption, firewall rules, and intrusion detection. We perform regular vulnerability scans and penetration testing.
Dependency management
We continuously monitor our software dependencies for known vulnerabilities and apply patches promptly. Our CI pipeline includes automated security scanning.
Data isolation
Customer data is logically isolated. Each account's scan data is accessible only to authenticated users within that account. We do not share data between accounts.
Incident response
We maintain an internal incident response plan. In the event of a security incident that affects your data, we will notify affected users within 72 hours and provide clear guidance on recommended actions.
Report a vulnerability
If you discover a security vulnerability in Alfacotex, we want to hear about it. We appreciate responsible disclosure and will work with you to address any confirmed issues promptly.
Please include a detailed description, steps to reproduce, and any proof of concept. We aim to acknowledge reports within 48 hours and provide a fix timeline within 5 business days.