Security & data isolation

You approve every change. We can't price without you.

You're handing over customers, revenue and pricing — and letting someone else work on them. Here's exactly how that data is isolated, encrypted and accessed, and who can see it, stated honestly: shipped controls are marked shipped, and items still being formalized are marked in progress rather than overclaimed.

Your approval gates every change

Shipped

No price, product, coupon or entitlement reaches your billing system without you approving it. Provisioning runs as a dry run first, rolls out by the cohort you choose, is journaled resource by resource, and is revertible per run. This is how the system is built, not a policy we promise to follow.

Who at Albi can see your data

In progress

Albi is a managed service, so a named pricing expert works inside your data — that is the service. They are staffed onto your account specifically and can see no other customer's. We are formalizing the written access and logging policy before stating specifics here.

Data isolation between customers

In progress

The account model (accounts / account_members / account_guests) isolates each customer's data — your first-party data never enters another engagement, and only the third-party market-intelligence layer is shared. The data model is built; the account-switcher UI is rolling out.

Per-project Stripe credentials

Shipped

You paste a Stripe API key with read scopes for each project; credentials are encrypted at rest, per project. Sync is read-only for analysis — writes happen only in the explicit provisioning step you initiate.

Auth & access control

Shipped

Supabase Auth with row-level security at the database, plus per-route auth enforcement in every API handler. The service-role client is used only server-side, never exposed to the browser.

AI provider

In progress

AI runs on Anthropic (Claude). Enterprise data-use terms are being finalized before we assert specifics here.

Encryption at rest & in transit

In progress

Client credentials are encrypted, and traffic is served over TLS. Specific standards and certifications (SOC 2, AES-256, TLS versions) are being formalized before we make a numbered claim.

No training on customer data

In progress

Customer data is used to run your engagement, not to train models. The full data-use posture is being documented and verified before publication.

The principle

Read-only by default. Writes only when you choose.

Across Baseline, Benchmark, Research, Value, Pricing and the Impact analysis, Albi reads from Stripe — it never edits it. The only writes happen in the provisioning step, after you have approved the design: run as a dry-run first, validated with sandboxed TestClock smoke tests, rolled out by cohort. Every provisioned resource is journaled and revertible, per resource and per run.

Questions about data handling?