Security & data handling
Alfred connects to your marketing stack read-only, synthesises what matters inside your own workspace, and delivers decision-ready intelligence — without taking control of your accounts, and without your data ever training anyone else's Alfred. This pack explains exactly how, in plain language.
Read-only by default
Alfred connects over secure read-only APIs. It can see your data; it cannot change it. Write-back is off until you explicitly authorise it, per integration.
Encrypted throughout
Every connection and every synced record is encrypted in transit and at rest. Credentials and OAuth tokens are stored encrypted and are revocable at any time.
Everything is logged
Every read, recommendation and authorised write lands in a full audit trail — who, what, when — exportable for your own review at any time.
No cross-customer training
Your workspace is isolated. Your data, your patterns and your outcomes are never used to train models for any other customer.
Where we are on certifications — the honest answer
SOC 2 Type II is in progress: the audit window is underway and the report is expected [DATE — confirm with security before sending]. A GDPR-aligned data-processing agreement is available on request. ISO 27001 is on the roadmap and not yet certified. Alfred does not display badges for certifications it has not earned — if a claim is not in this pack, do not make it.
The data-flow narrative
Three stages, one direction of trust: Alfred reads, reasons, and reports back. Nothing changes in your accounts unless you authorise it.
Connect — read-only
You connect your stack over secure read-only API and OAuth integrations — ad platforms, analytics, CRM, billing. Typical setup is under an hour with zero engineering, syncing up to a year of history. Alfred can see; it cannot touch.
Synthesise — in isolation
Synced data is normalised into your workspace's isolated store, where Alfred detects what changed, explains why, and recommends what to do next. Every recommendation carries its sources and a confidence score — never a black-box answer.
Deliver — and only act if asked
Briefs and alerts arrive in the app, email and Slack. If you enable write-back, Alfred acts in your tools only after explicit per-integration authorisation and an approval step — and every action is logged.
| Data category | What it includes | Where it lives | Retention |
|---|---|---|---|
| Connected-platform data | Campaign, spend, performance and pipeline records synced read-only | Encrypted at rest in Alfred's cloud infrastructure, [REGION — confirm current hosting region] | While your account is active; deleted within 30 days of termination |
| Workspace content | Briefs, recommendations, decisions, annotations, audit log | Your isolated workspace store — never pooled across customers | While active; exportable any time; deleted within 30 days of termination |
| Credentials | OAuth tokens and API keys for your integrations | Encrypted secret storage; never logged in plaintext | Revocable instantly — by you in Alfred, or at the platform side |
| Account & billing | Users, roles, invoices | Alfred's application database and payment subprocessor | As required for legal, tax and accounting obligations |
The current subprocessor list is maintained by our security team and provided with the DPA. Confirm this table is current before sending.
| Subprocessor | Purpose | Region | DPA status |
|---|---|---|---|
| [CLOUD PROVIDER] | Hosting & encrypted storage | [REGION] | [SIGNED / DATE] |
| [MODEL PROVIDER] | Model inference (no training on customer data) | [REGION] | [SIGNED / DATE] |
| [EMAIL PROVIDER] | Brief & alert delivery | [REGION] | [SIGNED / DATE] |
| [PAYMENTS PROVIDER] | Billing | [REGION] | [SIGNED / DATE] |
Access controls
RBAC is available on the Max and Enterprise plans. People see and do only what their role permits — nothing further.
| Role | Can do |
|---|---|
| Admin | Manage integrations, users, write-back authorisation and billing |
| Member | Read briefs, ask Alfred, propose and approve actions within their scope |
| Viewer | Read-only access to briefs and the KPI cockpit |
Every read, recommendation and authorised write is logged with who, what and when. The trail is exportable for review at any time — by you, without asking us.
Alfred syncs up to a year of history to build context. When you leave, you can export your workspace, and all customer data is deleted within 30 days of termination. Deletion earlier than that is available on request.
Prepared by E902 AI Labs Private Limited. This pack describes current architecture and practice; it is not a contractual commitment — contractual terms live in the MSA and DPA. Bracketed values must be confirmed with the security team before this document is shared externally.