LEGAL
Security
This page describes the security controls and operational protections used across PriorityEngine, the BSOS Developer Portal and the BSOS Partner Channel.
Last updated: August 29, 2026
1. Security approach
Alleria AI, Inc. designs its services with layered controls intended to protect accounts, business data, credentials, API access and tenant boundaries.
Security controls differ by product because PriorityEngine, the BSOS Developer Portal and the BSOS Partner Channel serve different operational purposes.
No internet-connected system can guarantee absolute security. Our objective is to reduce risk through authentication, authorization, encryption, credential lifecycle controls, tenant isolation and operational monitoring.
2. PriorityEngine account security
PriorityEngine account passwords are not stored as plaintext passwords. Passwords are stored usingPBKDF2-SHA256 password hashing.
Authenticated application access uses signed access tokens. Browser requests to authenticated PriorityEngine endpoints use the standard Authorization: Bearer mechanism.
Authentication secrets and application security keys are managed separately from application source code through the deployment environment.
3. Email connection credential protection
PriorityEngine supports authorized Gmail and IMAP connections. Connection credentials required to maintain these integrations are protected using application-level encryption before storage.
Gmail OAuth connection data and IMAP credentials are decrypted only when required by the application to perform an authorized email operation.
Disconnecting an email provider removes the stored connection information used to maintain that integration. Once disconnected, PriorityEngine stops importing new messages from that provider unless the account is explicitly connected again.
4. PriorityEngine workspace authorization
PriorityEngine separates workspace administration from normal team collaboration.
Workspace Owner
The workspace owner controls administrative and commercial operations, including subscription management, purchasing additional usage packs, managing team access and performing owner-restricted destructive actions.
Team Members
Team members may work with the business email workflows made available to them, including replies, follow-ups, internal notes and other permitted collaboration functions.
Team members cannot manage the workspace subscription, purchase additional usage packs or perform owner-restricted destructive operations.
5. Permanent Delete protection
Permanent Delete is restricted to the PriorityEngine workspace owner.
It is a manual, user-initiated operation and is never performed automatically. Before the operation is executed, PriorityEngine displays a confirmation warning explaining that the action is destructive and irreversible.
After explicit confirmation, PriorityEngine first attempts to permanently delete the selected email from the connected email provider. If the provider deletion succeeds, PriorityEngine then removes the message from the PriorityEngine inbox.
The operation cannot be undone.
6. PriorityEngine AI processing security
Certain PriorityEngine intelligence and AI-assistance functions use external AI processing.
Only information required for the requested analysis or assistance is provided to the applicable processing flow. Semantic analysis and AI Reply use different context depending on the function requested.
AI processing is used to provide product functionality such as classification, prioritization, trust-risk analysis and optional reply assistance.
Additional information about the data involved in these flows is available in ourPrivacy Policy.
7. BSOS tenant isolation
The BSOS Developer Portal is designed around organization-level tenant boundaries.
Applications, members, API credentials, capacity and related operational records are scoped to the authenticated organization.
Tenant checks are enforced in service and persistence logic for sensitive organization relationships and administrative actions.
A user or contact from one organization must not be bound to or used to administer another organization without an authorized relationship.
8. BSOS API-key security
BSOS stores a cryptographic hash of the API secret together with operational identifiers required to authenticate, identify and administer the credential.
The API-key model usesPBKDF2-SHA256 hashing and maintains separate public identifiers and credential metadata.
API keys are bound to the applicable organization, application, environment and access grant.
Credential permissions may also restrict authorized profiles, capabilities, data sources and execution modes.
9. BSOS API-key lifecycle controls
BSOS API credentials support controlled lifecycle states including:
- active;
- disabled;
- suspended;
- revoked.
The Portal maintains lifecycle metadata for expiration, revocation, disablement, suspension, last use, provisioning revisions and credential replacement where applicable.
Credentials may be rotated, replaced, disabled, suspended or revoked as required by security, provisioning or contractual conditions.
10. Credential compromise detection and recovery
BSOS includes controls for credential-security events and recovery.
Security notifications from the Runtime may be recorded by the Portal as durable security evidence. These records may include incident identifiers, credential identifiers, organization and application identifiers, event metadata and payload fingerprints.
The Portal maintains a controlled recovery lifecycle for supported credential-compromise incidents and coordinates authorized security controls with the Runtime.
Security-event evidence is maintained separately from arbitrary credential lifecycle mutation so recovery actions can remain explicit and auditable.
11. BSOS usage and capacity records
The BSOS Developer Portal maintains usage and capacity records required to administer processing entitlements and operational consumption.
The authoritative usage ledger stores operational metadata such as execution identifiers, organization, application, API key, environment, processing units, runtime version, pipeline version, engine version and timestamps.
The usage ledger is not designed as storage for the business content submitted to the BSOS Runtime for processing.
12. BSOS Customer Data
Customer Data submitted through BSOS remains the customer's data.
Alleria AI, Inc. receives only the limited rights necessary to process Customer Data in order to provide, operate, secure and maintain the BSOS service.
Additional contractual data-protection obligations may be defined in an applicable Data Processing Agreement or OEM agreement.
13. BSOS Partner Channel access security
The BSOS Partner Channel is invitation-controlled and does not provide unrestricted public partner signup.
Partner invitations are associated with an organization, email address, role, lifecycle status and expiration.
Invitation acceptance and applicable partner-terms acceptance may be recorded for audit purposes.
14. Partner Channel session security
Partner sessions are represented by server-side session records.
Raw session tokens are not stored directly in the session record. A token digest is maintained together with session lifecycle information such as creation, expiration, last activity and revocation timestamps.
Revoked or expired sessions are not intended to remain valid for authenticated Partner Channel access.
15. Partner organization and attribution controls
Partner users operate within their assigned partner organization and access is subject to tenant and role controls.
Partner Client Links, attribution records, sales and commissions remain associated with the applicable partner organization.
Attribution tokens are stored as hashes rather than as reusable plaintext token values.
16. Commercial record integrity
Partner Client Sales and commission records are maintained as separate commercial records.
Commission records preserve the historical commission base, rate, currency and calculated amount associated with the confirmed sale. This prevents a later commission-rate change from rewriting the historical value of a previously recorded commission.
17. Sensitive payout information
Sensitive banking, tax and legal-payee information required to process a partner payout is stored separately from the minimal payout audit record.
This sensitive payout submission may include legal payee details, registration or tax information, bank-account information, routing information and bank-country information.
Minimum commission and payout audit records may remain where necessary to document the commercial transaction.
Accounting evidence and beneficiary information retained by Alleria AI, Inc. through its accounting records, bank or payment provider are separate from the sensitive payout submission temporarily held in the Partner Channel.
18. Security monitoring and audit records
Our services may maintain operational, authentication, security, provisioning and audit records where necessary to investigate incidents, protect tenant boundaries, enforce permissions or document security-sensitive actions.
Access to security-sensitive functionality is limited according to the applicable role, service and administrative authority.
19. Secrets and configuration
Application secrets, encryption keys and service credentials are managed through protected deployment configuration rather than being intentionally embedded in public website content or exposed through user-facing interfaces.
Users must not attempt to obtain, expose, reuse or distribute another user's, customer's or service's credentials.
20. User security responsibilities
Security is a shared responsibility. Users and organizations should:
- use strong and unique account passwords;
- protect account and API credentials from unauthorized access;
- restrict account access to authorized personnel;
- remove users who no longer require access;
- rotate or revoke credentials when compromise is suspected;
- avoid sending credentials through insecure communication channels;
- report suspected unauthorized access promptly.
21. Security incidents
If we identify a security issue affecting a service, we may take protective actions such as restricting access, suspending a credential, requiring credential rotation, investigating the incident or applying recovery controls.
Where notification is required by applicable law or contractual obligation, affected customers or organizations will be notified according to the applicable requirements.
22. Third-party infrastructure and services
Our services depend on third-party infrastructure and technology providers for functions such as hosting, database services, email connectivity, AI processing and payment processing.
We select and configure providers according to the operational requirements of the applicable service, but no third-party system can be guaranteed to be completely free from security risk.
23. Vulnerability and security reports
If you believe you have discovered a security vulnerability in PriorityEngine, the BSOS Developer Portal or the BSOS Partner Channel, please report it responsibly and do not exploit the issue or access data beyond what is necessary to demonstrate the problem.
Security reports may be sent to:
Please include enough information for us to understand and investigate the reported issue. Do not include passwords, complete API secrets or unnecessary sensitive customer data in the report.
24. No absolute security guarantee
We maintain security controls designed to reduce risk, but no software, network, infrastructure or internet-connected service can guarantee absolute security.
We therefore do not describe our services as "unhackable", "100% secure" or otherwise immune from all security incidents.
25. Related policies
Information about personal-data processing is available in ourPrivacy Policy.
Information about deletion controls and account or organization closure is available on ourData Deletion page.
Browser storage and related technologies are described in ourCookie Policy.
26. Changes to this Security page
We may update this page as our services, infrastructure, security controls or legal requirements evolve.
The current version will be published with an updated "Last updated" date.
27. Contact
Security questions may be sent to:
Alleria AI, Inc.
Email:hello@priorityengineai.com