Security

Security that matches the rest of your stack.

GDPR compliant. SSO/SCIM with Okta, Google, Azure AD. AES-256 at rest, TLS 1.3 in transit. Every AI employee gets its own isolated VM, its own audit log, and nothing your team didn't sign off on.

Encryption

Encrypted in transit, at rest, in memory.

AES-256-GCM for everything we persist. TLS 1.3 on every hop. Short-lived credentials that never leave our control plane.

  • AES-256-GCM at rest
  • TLS 1.3 in transit
  • Ephemeral runtime secrets
  • HSM-backed key management
Isolation

One VM per employee. No shared memory.

Every AI employee runs in its own firecracker microVM. No cross-tenant execution. No ambient credentials. No shared filesystem.

  • Dedicated microVM per agent
  • Per-connection scoped OAuth
  • Network egress policies
  • No shared tool memory
Audit

Every action recorded and reversible.

Every tool call, every file write, every external hit is logged with the agent identity, input, output, and cost. Stream it to your SIEM.

  • Per-action immutable log
  • Reversible transactions
  • SIEM + warehouse export
  • Time-travel replay
Identity

Your directory, your rules.

SSO with Okta, Azure AD, Google. SCIM provisioning. Role-based access on everything from a template to a tool invocation.

  • SSO: SAML, OIDC
  • SCIM 2.0
  • Fine-grained RBAC
  • Optional regional data residency
Compliance

Compliance, in progress and in depth.

GDPR and CCPA compliant today. SOC 2 Type II in progress, ISO 27001 on the roadmap. Read our subprocessor list, pen-test summary, and DPA in the trust center.

GDPRActive

EU data subject rights + DPA

CCPAActive

California consumer privacy

SOC 2 Type IIIn progress

Security, Availability, Confidentiality

ISO 27001Roadmap

Information security mgmt

Practices

Operational commitments, not marketing copy.

Data residency

Pick US, EU, or UK for storage and compute — your data never leaves the region.

No training on your data

Customer data is never used to train models. Full stop. Contractual in every plan.

Vendor posture

Every subprocessor passes our security review. Full list published and versioned at the trust center.

Vulnerability disclosure

Report at security@alfera.ai. 24h acknowledgement, 30d fix SLA on criticals.

Incident response

Named incident commander, customer notification within 24h of confirmed breach.

Backups + DR

Point-in-time restore for 30d, tested DR runbook, RPO 5min / RTO 1h on Enterprise.

Build your first agent

Deploy your first AI employee in minutes.

No credit card required. Start with a template, connect your tools, and ship an agent before your next stand-up.