Security
Last updated: September 13, 2026
AlphaOriginal LLC is a small, independent software company. This page says plainly how we protect the information our products and this website handle, and how to reach us if you find a problem. Everything here is true today, not a goal.
How we run security
- A written policy, followed. We maintain a documented information security policy with procedures for risk management, access control, secure development, incident response, and recovery. Risks are tracked in a register that is reviewed every quarter, and routine checks are performed monthly and logged. The policy is reviewed at least once a year.
- Every account is protected. Multi-factor authentication is enabled on our source control, hosting, Apple Developer, and Google Workspace accounts. Every password is unique and kept in a password manager. Nobody shares logins.
- We collect as little as we can. Where a feature can work on your device, it does. We do not run advertising trackers, and we never see payment card numbers; Apple and Stripe handle payments for us.
- Every change is reviewed by a person before it ships. We use AI tools to help write software, and no secret or customer data is ever given to them.
- We are honest about what we have not done. We have not had a third-party penetration test and we hold no SOC 2 or ISO certification. Our hosting and payment providers do, and we rely on and review their controls.
This website
alphaoriginal.co is a static site with no JavaScript, no analytics, and no cookies. It is served over HTTPS with HTTP Strict Transport Security and a strict Content Security Policy. The only personal information it collects is what you type into the contact form, which is handled by our host, Netlify, and deleted within twelve months. Details are in our privacy policy.
Our products
- WaveSleep keeps your sleep journal, Apple Health data, and location on your device; none of it is sent to us. The app sends anonymous usage events to our analytics provider, described in full in the WaveSleep privacy policy.
- Bizvo is local-first: your invoices live in your browser, optional backups go to your own Google Drive or Dropbox, and card payments go straight to Stripe. Bizvo publishes its own security page.
- HueLux and Kreds are not yet released. Kreds will store the names of the cards in your wallet, never card numbers, and every release goes through a written pre-launch security review before it reaches the App Store.
Reporting a vulnerability
If you believe you have found a security issue in this site or any of our products, email security@alphaoriginal.co. Tell us what you found, where, and how to reproduce it. We will acknowledge your report within five business days, keep you informed while we fix it, and credit you if you would like. We do not run a bounty program.
We welcome good-faith research. If you make a genuine effort to avoid privacy violations, data destruction, and service disruption, and you give us reasonable time to fix an issue before disclosing it, we will not pursue legal action against you for that research. Our machine-readable contact details are at /.well-known/security.txt.
Questions
Business partners who need our full policy documentation for a security review can request it through the contact form; we share it under a non-disclosure agreement.