Security & trust

Security starts with who holds the keys. With Alloy, you do.

Alloy is software you run inside your own environment, not a service where you park assets. Your risk profile, your data and your keys stay where your regulators expect them.

How it is built

Four things your security team will want to know.

Your keys stay yours

Private keys live in your HSM or the signing provider you choose. Alloy holds no customer private keys.

It runs inside your perimeter

Deploy to your own cloud account or data center, behind your network, identity and monitoring controls.

Evidence by default

Requests, policy decisions and status changes are recorded and can be exported for audit and regulatory review.

Access you control

Roles for your people and scoped API keys for your services and agents, each with only the permissions it needs.

Security review

What review teams ask us first.

Is Alloy a custodian?

No. Alloy is software you operate. It holds no customer private keys and never takes possession of assets.

Where does our data live?

In your own environment. Alloy runs in your cloud account or data center, so transaction data stays inside your perimeter.

Can Alloy, the company, access our deployment?

Not by default. Your deployment runs in infrastructure you control, and access is granted on your terms.

What do you share for our review?

We walk your security and risk teams through where keys, data and decisions live, and share architecture and data-flow documentation for your review.

Bring your security review to us.

Tell us what your review needs and we will walk your team through it.