Alta VistaSecurity & Compliance
Alta Vista handles financial data for businesses and households, so the rules we run by are written down and published here. Each policy below describes controls that exist in the product today or commitments we have accepted, in plain English. They are version 1.0, effective September 2, 2026, and are reviewed at least annually.
Security questions, vulnerability reports, and data requests go to hello@myaltavista.com, which is monitored daily.
Policies
- Information Security Policy
The umbrella policy: how security is owned, what data we protect, and the standards every other policy builds on.
- Security Risk Management Policy
How security risks are identified, rated, treated, and re-examined, including the risk register that records them.
- Access Control Policy
Who can reach production systems and customer data, how identity is verified, and how access is granted, reviewed, and revoked.
- Change Management Policy
How code, schema, and configuration changes reach production: version control, automated gates, the schema-first deploy rule, and rollback.
- Logging and Monitoring Policy
What is logged, where, for how long, what must never appear in a log, and how logs are reviewed and alerted on.
- Incident Response Policy
How security incidents are detected, triaged, contained, and closed, and who is notified, when.
- Data Retention and Disposal Policy
How long each category of data is kept, how deletion and consumer requests are carried out, and how media is disposed of.
- Third-Party Risk Management Policy
How vendors that touch customer data are chosen, what we require of them, how they are reviewed, and the current subprocessor list.
How the product is built
- Tenant isolation is enforced by the database (row-level security with live membership lookups) and proven by an automated isolation test suite that runs on every change.
- All traffic is encrypted in transit; providers encrypt storage at rest; bank and accounting connection tokens are additionally encrypted at the application layer and stored where no API role can read them.
- Sign-in is passwordless (one-time emailed codes). Bank credentials are entered only in Plaid's hosted interface and never reach us.
- Every production account is protected by multi-factor authentication, and every change ships through version control and a CI gate that includes the isolation suite.
Subprocessors
The providers that run parts of the service on our instructions. None of them may use customer data for their own purposes.
| Provider | Role | Products |
|---|---|---|
| Vercel | Application hosting | All |
| Supabase (on AWS) | Database, authentication, file storage | All |
| Resend | Transactional email | All |
| GitHub | Source control and continuous integration | All |
| Plaid | Bank connections (read-only) | The Alta Vista Way |
| Anthropic | AI answers (Ask Claude); no training on your data | Alta Vista |
| Intuit | QuickBooks Online (read-only), when a client connects it | Alta Vista |
| A report rendered into a firm’s own Google Sheet, when the firm opts in | Alta Vista | |
| Slack | Staff notifications, when the firm opts in | Alta Vista |
Privacy
- Privacy Policy and Terms of Use for this site.
- Bank connections use Plaid; Plaid's handling of your data is described in the Plaid End User Privacy Policy.
- Access, correction, and deletion requests are answered within 30 days; see the Data Retention and Disposal Policy for how deletion is carried out.