Menu

Discover AlefOS

Discover AlefOS↗Your MCP, under your domain↗Features & integrations↗

Uses & integrations

Industry use cases↗All use cases↗Integrations↗

Your project

Deployment & pricing↗Request a demo↗Deployment↗

Resources & help

Resources↗Blog↗Customer support↗Client access↗Legal Center↗
Back to the home page ↗
AlefOS
EN⌄
English ✓Français

AlefOS Legal Center

Security

Security responsibilities and the scope of controls for the agreed services.

Version 2026.09 · Updated September 9, 2026

On this page
  1. Content Security Policy
  2. Frame protection
  3. HSTS
  4. Referrer and content-type headers
  5. Permissions Policy
  6. Authentication storage
  7. OAuth refresh
  8. MCP proxy
  9. Legal page indexing
  10. Access controls
  11. Team permissions
  12. Human approval

Content Security Policy

The public web server defines a Content Security Policy to restrict permitted content sources. Its protection concerns the responses on which the policy is sent; it does not guarantee the absence of injection on every interface.

Frame protection

Frame restrictions protect the relevant public pages against unauthorized embedding. Authentication and expressly embedded interfaces may need different policies; a policy observed on the marketing site is not automatically the policy of a Customer’s calling interface.

HSTS

HTTPS and transport-security headers protect the relevant served domain. Their scope must be verified for each deployed Customer domain; the company’s brand alone does not configure that protection.

Referrer and content-type headers

The public server uses referrer and content-type protections to limit unnecessary referral information and content-type confusion. These controls complement, rather than replace, authentication and permissions.

Permissions Policy

Browser feature permissions depend on the page. A calling interface may require microphone access and a user’s browser permission; granting it is distinct from company access rights and from any legal requirement to inform call participants.

Authentication storage

The current web client persists access-token state in the browser and uses an HttpOnly cookie for refresh. Browser storage is not described as exclusively server-side. The Cookie Policy explains the distinction between session access and data retention.

OAuth refresh

Session renewal and authorization flows maintain access within the granted scope. An OAuth connection does not grant authority to every company record or to any commercial purchase. Removing access and deleting previously imported data are distinct operations.

MCP proxy

Public product information, authenticated company use and Customer-specific MCP interfaces have different access scopes. A public product assistant is not evidence that it can read company records. The commissioned interfaces must apply the relevant user and company permissions.

Legal page indexing

Making a legal document discoverable helps people find it. Indexing or a canonical URL is not a security control protecting business data, and an unindexed preview is not an authenticated private space.

Access controls

MyBot undertakes appropriate access management and need-to-know controls for the agreed processing under the DPA. Specific measures and responsibilities belong in the project security description; no universal isolation guarantee or certification is inferred from this page.

Team permissions

Internal roles, assignments and explicit supervision determine access. Removing a collaborator’s authorization does not erase the company’s professional history. Administrators do not automatically have every right, and membership in several companies does not authorize sharing between them.

Human approval

External or committing AI-prepared actions, including WhatsApp messages, require human validation within the relevant permissions. Internal memory updates and configured service messages follow their own rules. A sent notification is not proof that the underlying work succeeded or that the recipient read it.

Legal Center · Terms of Use · Privacy Policy · Data Processing Agreement · Cookie & Session Policy · Refund Policy · Data deletion · Subprocessors · Data Retention · Privacy Requests · Legal Notice

Your work, in context.

Your business in ChatGPT and compatible assistants. Your domain, your permissions, continuity of work.

AlefOS
Discuss your project ↗Discover AlefOS ↗

Your environment

+
Discover AlefOSAI CRMTeam & permissionsDeploymentDeployment & pricing

Everyday work

+
IBOX · conversations & follow-upContacts & relationshipsGroups & teamworkCalendar & BookingMissions & responsibilitiesProducts & services

Your connections

+
Your MCP, under your domainWhatsApp BusinessCalls & CallOSCall providersMeeting providersIntegrations

Your industry

+
Real estateInsurance brokersMaintenance & field serviceConsulting firmsIndustry use casesAll use cases

Explore & get started

+
Features & integrationsResourcesBlogAI actions & human controlRequest a demoCustomer support

AlefOS operated by MyBot Ltd © 2026

Client accessLegal CenterPrivacyTerms
Français ↗