# Why Organizations Trust ALTCHA

ALTCHA is used by governments and organizations worldwide to protect forms from bots without compromising user privacy. This page lays out the concrete reasons why — not just claims.

## Proven at scale

ALTCHA is the **#1 privacy-first CAPTCHA widget**, with **250,000+ live websites** according to [builtwith.com](https://trends.builtwith.com/widgets/ALTCHA).

## Built for compliance

ALTCHA and its products are designed to comply with strict data protection and accessibility standards by default:

- **Data protection** — [GDPR](/legal/compliance/gdpr/), [HIPAA](/legal/compliance/hipaa/), [CCPA](/legal/compliance/ccpa/), [PIPEDA/CPPA](/legal/compliance/cppa/), [LGPD](/legal/compliance/lgpd/), [DPDPA](/legal/compliance/dpdpa/), and [PIPL](/legal/compliance/pipl/).
- **Accessibility** — [WCAG 2.2 AA](/legal/compliance/wcag/) and the [European Accessibility Act (EAA)](/legal/compliance/eaa/).
- **Enterprise deployments** — the [Security Compliance Framework](/legal/security-framework/) for ALTCHA Sentinel is aligned with SOC 2, ISO 27001, GDPR, HIPAA, and other global standards.

See the full [Regulatory Compliance](/legal/compliance/) overview for details on each.

## Security by design

- Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA)
- Encryption in transit and at rest
- Comprehensive audit logging, with support for exporting logs to external systems
- A Software Bill of Materials (SBOM) for transparency
- Zero-CVE Docker images — every [Sentinel release](/docs/sentinel/releases/) ships a Trivy scan alongside its pentest and vulnerability reports, published in full for transparency
- A published [Security Vulnerability Disclosure Policy](/legal/security/) and [Security Advisory](/legal/security-advisory/) history

## Data sovereignty and ownership

- **No third-party data sharing** — ALTCHA doesn't transmit or store visitor data externally, and uses no tracking cookies or fingerprinting.
- **Self-hosted option** — run [Sentinel](/docs/sentinel/) entirely on your own infrastructure, with perpetual licensing so it remains an asset you control.
- **EU-hosted Cloud** — [ALTCHA Cloud](/docs/cloud/) is hosted exclusively in the EU.
- **Air-gapped deployment** — offline license verification is supported for environments that can't allow outbound call-home traffic.

See [Open Source vs. Paid](/docs/open-source-vs-paid/) for how these options compare.

## Open and auditable

ALTCHA's widget and verification libraries are open source, MIT licensed, and published on [GitHub](https://github.com/altcha-org) — your team can inspect exactly what's running rather than taking a vendor's word for it. See [Open-Source CAPTCHA](/open-source-captcha/) for details.

## Built and operated in the EU

ALTCHA is built and operated in the European Union, with a strong focus on privacy, security, and data sovereignty — from keeping data under your control to meeting demanding European privacy and compliance requirements.

## Next steps

- **[Regulatory Compliance](/legal/compliance/)** — the full list of supported standards
- **[Solutions](/docs/solutions/)** — guidance by organization type, including [Governments](/docs/solutions/governments/) and [Enterprises](/docs/solutions/enterprises/)
- **[About](/about/)** — the people and values behind ALTCHA
- **[Contact](/contact/)** — questions about compliance, security, or procurement
