Trust & Security
Security at Alliance Enterprise System
Security is fundamental to how Alliance Enterprise System LLC supports customers, partners, suppliers, and public-sector organizations. We work to protect information, systems, communications, and business processes through appropriate administrative, technical, and organizational safeguards.
Last updated
Six principles behind every safeguard.
These principles shape how we select, apply, and review the security measures described on this page.
Protect Confidentiality
Keep business, customer, and supplier information available only to people and systems with a legitimate need.
Maintain Integrity
Guard information and systems against unauthorized or accidental alteration.
Support Availability
Keep important business processes and records reliable and recoverable.
Minimize Access
Grant the access a role requires, and review it as responsibilities change.
Respond Responsibly
Assess, contain, and communicate security events in line with our legal and contractual obligations.
Continuously Improve
Adapt safeguards as threats, technology, and customer requirements evolve.
On this page
Our Security Approach
Alliance Enterprise System LLC takes a risk-based approach to information security.
Our objective is to protect business information and technology resources against unauthorized access, disclosure, alteration, misuse, disruption, or loss while supporting reliable business operations.
Security measures are selected based on factors such as:
- sensitivity of information
- business requirements
- customer obligations
- system risk
- applicable contractual requirements
- applicable law
- evolving security threats
Access Control
We seek to limit access to systems and business information according to legitimate business need.
Security practices may include:
- role-based access principles
- authentication controls
- least-privilege practices
- account lifecycle management
- administrative access controls
- periodic access review
Data Protection
We apply reasonable safeguards to protect personal, commercial, customer, supplier, and business information.
Depending on the system and service involved, safeguards may include:
- secure transmission
- encryption capabilities
- access controls
- secure storage
- logging
- backup processes
- data minimization
- retention controls
Our Privacy Policy explains how personal information is collected, used, and protected.
Infrastructure and Application Security
Where applicable, our technology practices may include:
- secure configuration
- patch management
- dependency management
- vulnerability management
- endpoint protection
- network security
- secure development practices
- logging and monitoring
- backup and recovery
- change controls
Third-Party Risk
Alliance Enterprise System LLC works with technology providers, manufacturers, distributors, cloud providers, professional-service providers, and other third parties.
We consider security, contractual obligations, service requirements, and business risk when selecting and managing relevant providers.
Third-party products and services may also be governed by their own security practices and terms.
Incident Response
We maintain processes intended to support identification, assessment, containment, investigation, remediation, and communication of security incidents.
Where notification is required by applicable law or contract, we seek to provide required notices in accordance with applicable obligations.
Business Continuity
We take reasonable steps to support continuity of important business operations and recovery from technology or operational disruptions.
Continuity measures may vary depending on the service and business process involved.
Secure Customer Communication
Please do not send sensitive data over unsecured channels
Customers and partners should avoid transmitting passwords, payment credentials, sensitive personal information, export-controlled technical information, or other highly sensitive data using unsecured communication channels unless specifically instructed to do so through an approved secure process.
Responsible Vulnerability Disclosure
We welcome responsible reports from security researchers and other individuals who believe they have identified a vulnerability affecting a system operated by Alliance Enterprise System LLC.
Before submitting a report
Researchers should:
- act in good faith
- avoid privacy violations
- avoid accessing unnecessary data
- avoid disrupting systems or services
- avoid social engineering
- avoid denial-of-service activity
- avoid destructive testing
- provide sufficient information for investigation
- allow reasonable time for remediation before public disclosure
Do not
- download unnecessary data
- alter customer information
- attempt extortion
- exploit vulnerabilities beyond what is necessary to demonstrate the issue
- access third-party systems not operated by Alliance Enterprise System LLC
Reporting a Vulnerability
Submit vulnerability reports through our official contact form and label the submission Security Vulnerability Report. The button below opens the form with that label already selected.
Please include:
- affected page or system
- vulnerability type
- reproduction steps
- technical impact
- screenshots or evidence
- contact information
Keep sensitive details out of the first message
Describe the issue without including passwords, access tokens, or personal data in your first message.
Security Certifications
Certifications and independent assessments
Security certifications and independent assessments applicable to specific services may be provided to eligible customers when available.
Security Contact
For security-related questions, contact us through the Contact page. Our Ethics & Compliance page explains how to raise other compliance concerns.
