Can Alloy access my private keys or sign transactions on my behalf?
No. Alloy's architecture does not include any mechanism to access, store, or generate private keys. Transaction signing is performed by your custody provider through their standard signing flow. Alloy submits transaction requests via provider APIs — the same APIs your team already uses directly.
What happens to my operations if Alloy goes down?
Your custody providers continue to function independently. All transactions previously submitted are already with the provider. Audit evidence and reconciliation records exported before the outage remain in your systems. Alloy is an operational layer, not a dependency in the critical signing path.
Is Alloy SOC 2 certified?
Not yet. Alloy is an early-stage company currently in design partner validation. SOC 2 Type I readiness is on our compliance roadmap for months 6–12 post-seed, with Type II audit engagement planned for month 12+. We are transparent about this because we believe honesty about compliance stage is more useful than vague claims.
How is my provider API credential stored?
Provider API keys and OAuth tokens are encrypted at rest using AES-256 with per-tenant encryption keys stored in dedicated secret management infrastructure. Credentials are never logged, never exposed in API responses, and never accessible to Alloy personnel without a formal access request process.
Can Alloy employees see my transaction data?
Production data access requires explicit justification, MFA authentication, and is fully logged. Routine operations do not require access to customer data. Support cases that require data access follow a documented process with time-limited permissions and audit review.
Does Alloy need a custody license?
Based on our assessment, Alloy's non-custodial architecture — which never holds, controls, or has access to private keys or customer funds — does not trigger custody-specific licensing requirements in the jurisdictions we operate in. However, regulatory landscapes evolve. Customers should consult their own legal counsel for jurisdiction-specific guidance. We are happy to provide architectural documentation to support your legal team's assessment.
Can I get a security questionnaire or evidence package?
Yes. Contact security@alloy.build for our current security documentation, architecture diagrams, and control descriptions. We are building toward a self-service Trust Center with live compliance status for later stages.