Trust & security
How we design Alegria RevOps to keep revenue data isolated, access controlled and AI actions reviewable. These are our own commitments as the operator of this product.
Tenant isolation
Every workspace is a separate tenant. Application data is scoped per organization and enforced in the database with row-level security policies, so one workspace cannot read another workspace's records.
Access control
Roles are stored separately from user profiles and checked server-side. Members only see the areas their role allows, and sensitive operations such as billing, governance and platform administration are gated by explicit permissions.
Credentials and connections
CRM and notetaker credentials are stored per tenant and encrypted at rest with AES-256-GCM. Keys are never returned to the browser, and connections can be disconnected at any time from the Integrations page.
AI usage and human review
AI agents are governed: their prompts, models and permitted actions are configured per workspace, runs are logged, and changes that write back to your CRM require human approval before they are applied.
Auditability
Agent runs, approvals and write-backs are recorded in an audit log with the acting user, timestamp and the record affected, so you can reconstruct what an automation did and why.
Reporting a vulnerability
Email support@alegriarevops.com with steps to reproduce. Please do not publicly disclose an issue before we have had a chance to respond. We aim to acknowledge reports within two business days.
Compliance questions
We have not published third-party certifications for this product. If you need specific compliance documentation for a vendor review, contact us and we will tell you exactly what we can provide today.