Alta Vista

Security & Compliance

Alta Vista handles financial data for businesses and households, so the rules we run by are written down and published here. Each policy below describes controls that exist in the product today or commitments we have accepted, in plain English. They are version 1.0, effective September 2, 2026, and are reviewed at least annually.

Security questions, vulnerability reports, and data requests go to hello@myaltavista.com, which is monitored daily.

Policies

  • Information Security Policy

    The umbrella policy: how security is owned, what data we protect, and the standards every other policy builds on.

  • Security Risk Management Policy

    How security risks are identified, rated, treated, and re-examined, including the risk register that records them.

  • Access Control Policy

    Who can reach production systems and customer data, how identity is verified, and how access is granted, reviewed, and revoked.

  • Change Management Policy

    How code, schema, and configuration changes reach production: version control, automated gates, the schema-first deploy rule, and rollback.

  • Logging and Monitoring Policy

    What is logged, where, for how long, what must never appear in a log, and how logs are reviewed and alerted on.

  • Incident Response Policy

    How security incidents are detected, triaged, contained, and closed, and who is notified, when.

  • Data Retention and Disposal Policy

    How long each category of data is kept, how deletion and consumer requests are carried out, and how media is disposed of.

  • Third-Party Risk Management Policy

    How vendors that touch customer data are chosen, what we require of them, how they are reviewed, and the current subprocessor list.

How the product is built

  • Tenant isolation is enforced by the database (row-level security with live membership lookups) and proven by an automated isolation test suite that runs on every change.
  • All traffic is encrypted in transit; providers encrypt storage at rest; bank and accounting connection tokens are additionally encrypted at the application layer and stored where no API role can read them.
  • Sign-in is passwordless (one-time emailed codes). Bank credentials are entered only in Plaid's hosted interface and never reach us.
  • Every production account is protected by multi-factor authentication, and every change ships through version control and a CI gate that includes the isolation suite.

Subprocessors

The providers that run parts of the service on our instructions. None of them may use customer data for their own purposes.

ProviderRoleProducts
VercelApplication hostingAll
Supabase (on AWS)Database, authentication, file storageAll
ResendTransactional emailAll
GitHubSource control and continuous integrationAll
PlaidBank connections (read-only)The Alta Vista Way
AnthropicAI answers (Ask Claude); no training on your dataAlta Vista
IntuitQuickBooks Online (read-only), when a client connects itAlta Vista
GoogleA report rendered into a firm’s own Google Sheet, when the firm opts inAlta Vista
SlackStaff notifications, when the firm opts inAlta Vista

Privacy

  • Privacy Policy and Terms of Use for this site.
  • Bank connections use Plaid; Plaid's handling of your data is described in the Plaid End User Privacy Policy.
  • Access, correction, and deletion requests are answered within 30 days; see the Data Retention and Disposal Policy for how deletion is carried out.