Alex suite

Explore the Alex suite

One family of tools for Hamilton County. Choose where to go next.

Invest Hamilton County

Alex is one part of what Invest Hamilton County does. Explore the rest.

Trust center

How Alex protects and explains your data

Alex serves cities, schools, employers and community organizations, and some of what they entrust to us is sensitive. This page states what is running today, what is only aligned to a framework, and what no one has audited yet.

Last reviewed
August 2026
Independent attestation
None yet

What this covers

Everything below applies to the Alex platform: the audience portals at alexhamiltoncounty.com, the civic portals operated for cities and the county, and the specialist dashboards. Deployments run by a licensee on their own infrastructure are theirs to operate; we describe the seams and the disclaimers they inherit, not their controls.

How to read the status on each control

Operating
The control runs today, across the platform. If you ask, we will show you where.
Aligned
Built against a named framework's criteria. Alignment is a statement about how we build. It is not an audit and does not become one by repetition.
Independently attested
A third party examined it and issued a report. Nothing on this page currently carries this status.
Project-specific
Applies to an engagement that asked for it, not to the platform by default. We state in writing which of these apply to your deployment.

Controls and evidence

Operating

Access

Production surfaces are gated: enterprise identity (Auth0) on member portals, scoped access codes on partner surfaces, and contract-gated provisioning on licensed modules. Sessions use hardened cookie settings; administrative actions are logged.

Evidence: access review on request.

Operating

Change management

Every application is version-controlled with a full change history. Our most critical files run under a canon governance protocol: modification requires an explicit typed override, and file hashes are verified against a baseline on a recurring schedule.

Evidence: override log and baseline report on request.

Operating

Data protection

TLS everywhere; strict security headers (CSP, HSTS, frame denial) on hardened surfaces; secrets in environment configuration, never in code; data minimization by design, including zero-retention patterns on our most sensitive tools and aggregation floors on small-population statistics.

Evidence: header scan and retention posture per surface.

Operating

Evidence and audit trails

Where documentation matters most we use append-only, hash-chained ledgers, so records are tamper-evident and every export carries verifiable provenance.

Evidence: a chain segment and its verification, on request.

Operating

Availability

Independent external uptime monitoring with alerting, health-check endpoints on every service, scheduled backups with documented restore runbooks, and recovery-time objectives per system class.

Evidence: monitor history and the restore runbook for your system class.

Operating

Vendors

A small, reviewed set of subprocessors (hosting, identity, email, analytics), documented in our vendor register with a risk tier for each.

Evidence: the vendor register, on request.

Aligned

SOC 2 control framework

We maintain controls aligned to the AICPA Trust Services Criteria across security, availability and confidentiality. That describes how we build and operate. It is not a certification.

Evidence: the control mapping, on request.

Project-specific

Attestation-grade build

When an engagement warrants it we apply the SOC 2 build checklist from the first commit: scoped access reviews, audit logging on authentication and administrative events, rate limiting, pinned dependencies, backup wiring, and an incident-response runbook naming real people. Your project inherits the framework rather than paying to invent it.

Evidence: the checklist, and which items your deployment carries, in writing.

Where the claims stop

No system described on this page holds a SOC 2 report today. We do not claim SOC 2 certification or compliance, and we will not, until an independent auditor has issued a report for the system in question. If your procurement requires one, ask: the readiness work is done, which makes the attestation a scheduling decision rather than a rebuild.

We will always tell you in writing precisely which of these controls apply to your deployment, including the ones that do not.

Report a concern, or ask for evidence

Security reports and evidence requests go to the same place, are read by a human, acknowledged, and tracked to resolution under our incident-response plan.

Contact the team How Alex handles your data

Ask Alex

Help, sources, and feedback for this page.

View sources How Alex sources and cites every number Contact support Reach the Invest Hamilton County team