Security and privacy
Last updated: June 22, 2026
At 3 Alpha IA we design AI agents with security and privacy built in from the start. We apply practices and controls proportionate to each project's scope, data and risk.
1. Security by design
We integrate security and privacy by design from project planning, with specific requirements evaluated based on scope and risk.
2. Data minimization
We aim to collect and process only information necessary for the agreed purpose.
3. Access and least privilege
We limit access to data and systems based on project roles and needs, subject to applicable contractual agreements.
4. Project-specific infrastructure
Projects may be deployed on client infrastructure or selected cloud infrastructure depending on each project's technical, security and contractual requirements.
5. Client data
When possible, we prioritize client-controlled environments for project data processing.
6. Providers and subprocessors
We evaluate providers based on project needs. Applicable providers are documented where appropriate in proposals, contracts or DPAs.
7. Security incidents
We maintain processes to identify, contain, investigate and communicate security incidents in accordance with applicable contractual obligations.
8. Evaluation, monitoring and quality
Agents may include evaluations, monitoring, alerts and human review to identify quality degradation or unexpected behavior, as agreed in scope.
9. Security requests
For security requests, write to support@3alphaia.com.
Projects requiring security questionnaires, NDAs, DPAs, security annexes, architecture review or regulatory requirements are evaluated individually before corresponding data processing begins.
10. Scope of certifications
We do not claim specific compliance certifications, reports or validations such as SOC 2, HIPAA or ISO 27001 unless expressly stated in writing in applicable official documentation.