Stablecoin payments are up 42% in 2026.
Read the new report →
Solutions
By Use Case
Academia
Finance & Operations
Investment Research
Issuance
Market Oversight
Payments
Product & Engineering
Trading & Investment
Explore
Chain Directory
Compare Solutions
Clients
By Organization
Accounting & Audit Firms
Asset Managers
Banks
Exchanges
Hedge Funds
Payment Networks
Stablecoin Issuers
Products
Allium AI
Allium Terminal
Historical Data
Explorer
Datashares
Real-Time Data
Developers
Datastreams
Research
Resources
Insights
Blog
Digital Asset Identifiers (DASID)
Trust Center
Company
About
Careers
Partners
Partner Programs
Snowflake
Databricks
Docs
Log In
Get a Demo
Sign Up
Sign Up
Log In
Get a Demo

Security and privacy at Allium

SOC II Compliant

Allium is committed to protecting the confidentiality, integrity, and availability of data in our possession. This security policy outlines the measures and guidelines we follow to ensure the security of our data assets, information systems, and infrastructure. All employees, contractors, and third-party partners are expected to comply with this policy to maintain a secure environment for our data.

Information Classification

Data Classification

All data within Allium is classified based on its sensitivity and criticality. The following classification levels are defined:

  1. Highly Sensitive: Data that, if disclosed, could result in significant harm to individuals or the company, or a violation of legal or regulatoryrequirements.
  2. Sensitive: Data that requires protection due to privacy or business considerations.
  3. Internal Use: Data that is intended for internal use only and has no specific privacy or business sensitivity.
  4. Public: Data that can be freely disclosed without any restrictions.

Data Handling

Data handling procedures are followed based on their classification:

a. Highly Sensitive and Sensitive Data:

Access is limited to authorized personnel.
Encryption is used for data in transit and at rest.
Data is securely stored and transmitted.
Data is regularly backed up and tested for restoration.
Data is securely disposed of when no longer needed.

b. Internal Use Data:

Access is limited to employees with a legitimate need.
Encryption is used for data in transit and at rest when appropriate.
Data is stored and transmitted securely.

c. Public Data:

Access can be granted to the general public without restrictions.
Protection mechanisms are implemented to prevent unauthorized modifications.

Access Control

User Access Management

Access to information systems and data is granted on a need-to-know basis, following the principle of least privilege. The following practices are implemented:

  1. User accounts are created for individual employees and tied to their unique identities.
  2. Access privileges are granted based on job responsibilities.
  3. User access is promptly revoked or modified upon employee termination, transfer, or change in responsibilities.
  4. Strong passwords are enforced, and multi-factor authentication (MFA) is utilized for critical systems and privileged accounts.
  5. Regular audits and reviews of user access rights are conducted to ensure compliance.

Remote Access

Remote access to company systems are governed by the following guidelines:

  1. Remote access are granted based on business requirements and user needs.
  2. Secure connections, such as virtual private networks (VPNs), are used for remote access.
  3. All remote access sessions are logged and monitored for suspicious activities.

​Network and Infrastructure Security

Network Security

Allium maintains a secure network environment by implementing the following measures:

  1. Firewalls and intrusion prevention systems (IPS) are in place to protect the network from unauthorized access and malicious activities.
  2. Network traffic is monitored for anomalies and security events.
  3. Wireless networks are secured with strong encryption and access controls.
  4. Regular vulnerability assessments and penetration testing are performed to identify and address security weaknesses.

System and Application Security

Systems and applications is secured by adhering to the following practices:

  1. Regular patch management are implemented to ensure systems and applications are up to date with security patches.
  2. Antivirus and anti-malware software are installed and regularly updated on all systems.
  3. Secure configurations and hardening guidelines are followed for all systems and applications.
  4. Secure coding practices are followed during application development to minimize vulnerabilities.

Incident Response and Reporting

Allium has an incident response plan in place to address security incidents promptly and effectively. The following procedures are followed:

  1. All employees are aware of the incident reporting process and promptly report any security incidents or suspected breaches.
  2. Incidents are documented, investigated, and escalated as appropriate.
  3. Remediation actions are taken to mitigate the impact of the incident and prevent future occurrences.
  4. Lessons learned from security incidents are documented and used to improve security controls and processes.

Security Awareness and Training

Allium applies security awareness and training programs to employees, contractors, and third-party partners. The training covers the following areas:

  1. Information security policies and procedures.
  2. Data classification and handling.
  3. Password management and best practices.
  4. Social engineering and phishing awareness.
  5. Reporting security incidents.

Compliance and Auditing

Allium complies with all applicable laws, regulations, and industry standards. Regular security audits and assessments are conducted to evaluate the effectiveness of security controls and identify areas for improvement.

Policy Review and Updates

This security policy is reviewed periodically and updated as necessary to reflect changes in the organization, technology, and regulatory landscape. All employees are notified of policy updates and trained accordingly.

By adhering to this security policy, Allium aims to protect its data assets, ensure the privacy of individuals, and maintain the trust of its customers and stakeholders.

Stay updated with the latest news and insights in onchain data.
Solutions
Academia
Finance & Operations
Investment Research
Issuance
Market Oversight
Payments
Product & Engineering
Trading & Investment
Chain DirectoryCompare Solutions
Products
Allium AI
Allium Terminal
Datashares
Datastreams
Developers
Explorer
Company
AboutCareersPartner ProgramsSnowflakeDatabricks
Resources
InsightsBlogResearch HubTrust CenterDocs
© 2026 Allium. All rights reserved.
Terms of ServicePrivacy PolicySecurity and Privacy

Join Allium Research

Onchain research on stablecoins, tokenized assets, and prediction markets, straight to your inbox.