Security

Control is not an add-on.

AlterX is designed so that access, permissions, human checkpoints and evidence remain part of the mission, not separate from it. AlterX is designed to support and enforce these controls — formal audits and certifications will be published only when completed.

Request security information
01

Identity and access

Access is identity-based. Roles define who can create missions, approve actions, connect systems and export evidence.

02

Workspace separation

Missions, data, workflows and evidence stay inside their workspace. Separation is structural, not cosmetic.

03

Permissioned connections

Every connected system carries explicit scope. Missions can be configured to never exceed the granted permissions.

04

Human approval boundaries

Sensitive actions are designed to pause for the person with authority — with the action, reason, scope, risk and rollback in front of them.

05

Data handling and retention

What is kept, and for how long, is a configuration. Retention supports the evidence model without becoming an accidental archive.

06

Audit and evidence

Decisions, approvals, artifacts and checks keep their trail. The record is designed to survive review.

07

Availability and resilience

The service is designed for graceful degradation — failures are classified and surfaced, not hidden.

08

Responsible AI and evaluation

Outputs are designed to be checked against criteria before acceptance. Weak steps can be returned for revision instead of shipped.

Language on this page is deliberately qualified — "designed to", "supports", "can be configured to". Security and retention behaviour depends on the configured plan and deployment. Additional security information is available during evaluation.

Suspected vulnerabilities: alterx@alterx.co.in — subject line "Security enquiry".

Privacy, terms, acceptable use and the DPA are published as review drafts. Certifications appear only when completed.