Security
Practical, defensible defaults — not a checklist of marketing buzzwords.
Encryption everywhere
All traffic to and from alifTeams is served over TLS 1.2+. Data at rest in PostgreSQL is stored on encrypted volumes; uploaded files are encrypted at rest in our object storage. Backups are encrypted with separate keys.
Authentication
Passwords are hashed with bcrypt (cost 12). Sessions are signed JWTs in httpOnly, Secure, SameSite=Lax cookies that expire after five days and slide forward while you're active. Confirming your email address is required before you can post, invite anyone or upload a file. Credential endpoints are rate-limited per IP. SAML / OIDC single sign-on is not available yet — it is on the Enterprise roadmap and we will say so plainly rather than list it as shipped.
Workspace isolation
Every API call is scoped to the requesting workspace member. Cross-tenant access is denied at the query layer — even an admin in one workspace cannot read another workspace's messages, files, or task lists.
AI agents
Agents are opt-in: nothing is sent to a model provider unless someone @-mentions an agent in a message. Prompts go through our own gateway to OpenAI under API terms that exclude your data from training. We record token counts and cost per call so usage limits can be enforced, and we never sell prompts or completions.
Data location & retention
All data is held in the United States today. A choice of region is something we arrange per customer under an Enterprise agreement, not a switch in the product. Your messages are kept until you delete them or delete the workspace; on Free, search reaches back 30 days, and paid plans search the full history. Deleting a workspace purges its data within 30 days.
Backups & disaster recovery
PostgreSQL is dumped nightly, kept for 14 days locally and copied off the application host to object storage. Restores are exercised by hand rather than on a published schedule — we would rather tell you that than claim a drill cadence we don't run yet.
Vulnerability disclosure
If you find a security issue, please email hello@alifteams.com. We acknowledge reports within 48 hours and we credit researchers (with permission) in our security log.