How we protect your account and your information
ALFA Manufacturing Group · Last updated 2026-09-10
ALFA OS holds customer formulas, pricing, orders and our own books, so it is built to be used only by the people who should use it, and to leave a record of what they did. This page describes the safeguards in plain terms. It is a description, not a guarantee — see the Terms of Use — but it is accurate as of the date above, and we update it when the system changes.
1. Two-step sign-in
Every login is a password plus a second step. The second step can be a one-time code sent by text message to the phone on file, a code from an authenticator app, or the face or fingerprint unlock already on your phone or computer. The biometric option uses the WebAuthn standard: the check happens on your device, the device sends us only a signed confirmation, and your biometric data never leaves it — ALFA MFG never receives or stores a face or fingerprint. Text-message codes expire quickly and work once.
2. Idle sign-out
A session that sits untouched for one hour is signed out automatically (the company owner’s own session is the one exception, by his choice). Signing out clears the session on the server, not just in the browser, so a stale tab cannot be picked up later. Portal customers on a *.vercel.app address are redirected to the canonical domain so the session cookie is only ever set on the real site.
3. Encryption
All traffic between your browser and ALFA OS is encrypted with TLS (HTTPS); plain HTTP is not served. Data at rest — the database, uploaded files and backups — is encrypted by our hosting providers (Supabase and Vercel) using industry-standard AES-256 encryption. Passwords are never stored; only a salted hash is. Payment card details never touch our systems at all — Stripe collects them directly.
4. Access by role
Every person has a role and a set of modules they can open; the rest of the application is simply not there for them. Portal customers see only their own company’s records, enforced on the server for every query — a customer cannot reach another customer’s data by guessing an address. Staff access is granted per module and reviewed when someone’s job changes or they leave. AI assistants run under the same gates as the person using them and cannot see what that person cannot see.
5. Audit trail
The accounting ledger is append-only in practice: entries are never lumped or silently rewritten, corrections recategorise the original line with its date and the person who changed it, and every entry carries the party it belongs to. Bank and card transactions come from the bank feed and cannot be moved to another account. Consent records (terms acceptance, text opt-in) store the date, IP and browser. Remote-assist sessions between staff members are logged — who helped whom, when, and whether control was allowed. These records are what a CPA signs off on and what we produce if a question ever arises.
6. Service providers
The providers that host or process data for us (Supabase, Vercel, Stripe, Plaid, Twilio, Microsoft 365 and the others listed in the Privacy Policy) each publish their own security attestations (SOC 2, ISO 27001 or equivalent). We use their managed services rather than running our own servers, and we keep the keys that connect us to them in the hosting platform’s secret store, never in code.
7. Reporting a security issue
If you find a vulnerability, receive a suspicious message that looks like it came from us, or think a login has been misused, tell us before telling anyone else. Email info@alfamfg.com with what you saw and how to reproduce it. We will acknowledge within two business days, keep you informed, and will not take action against anyone who reports in good faith and does not access, change or share data beyond what is needed to show the problem.
Write to ALFA Manufacturing Group, 17401 NW 2nd Ave, Ste 7, Miami Gardens, FL 33169, or email info@alfamfg.com. We answer within a reasonable time and never charge for a request about your own information.
