Security is foundational to how TECHALEXUS LLC builds and operates AI automations. This page summarizes the practices we use to protect our clients' data and systems. Specific controls may vary by engagement and are described in the applicable agreement and Data Processing Addendum.
1. Our commitment
We design our services around the principles of confidentiality, integrity, and availability. We collect and retain only the data we need, limit who can access it, and build automation that is auditable and reliable.
2. Encryption
- Data in transit is protected using industry-standard TLS encryption.
- Data at rest is encrypted using the encryption provided by our reputable cloud and platform providers.
- Secrets and credentials are stored in secured secret managers, never in plain text in code.
3. Access control
- We follow the principle of least privilege — people and systems receive only the access they need.
- Access to client systems and data is granted on a need-to-know basis and revoked when no longer required.
- We use strong, unique credentials and enable multi-factor authentication on supported accounts.
4. Infrastructure & hosting
We build on established cloud and SaaS providers that maintain robust physical and network security and recognized compliance certifications. We rely on their hardened infrastructure rather than operating our own data centers, and we configure services following provider security best practices.
5. Application security
- We follow secure development practices and review changes before they reach production.
- We keep dependencies up to date and address known vulnerabilities promptly.
- We validate inputs and apply safeguards against common web application risks.
6. AI & model security
- We use reputable AI providers and respect their data-use and retention controls, opting out of training on client data where such options are available.
- We design agents with guardrails, scoped permissions, and human-in-the-loop checkpoints for sensitive actions.
- We minimize the data shared with models to what is necessary for the task.
7. Monitoring & logging
We monitor the automations we operate and maintain logs that help us detect issues, troubleshoot, and provide accountability, consistent with applicable data-protection requirements.
8. Vendor & subprocessor management
We select third-party providers with strong security postures and bind them to appropriate confidentiality and data-protection terms. Our use of subprocessors is described in our Data Processing Addendum.
9. Backups & continuity
We rely on the redundancy and backup capabilities of our cloud providers and maintain configurations and documentation so that services can be restored in the event of disruption.
10. Incident response
If we become aware of a security incident affecting client data, we will investigate, take steps to contain and remediate it, and notify affected clients without undue delay in accordance with our agreements and applicable law.
11. Shared responsibility. Security is a partnership. Clients are responsible for managing access to their own accounts, using strong authentication, granting only the integrations required, and ensuring their use of automations complies with applicable laws and our Acceptable Use Policy.
12. Report a vulnerability
We welcome responsible disclosure. If you believe you have found a security vulnerability in our website or services, please email contact@techalexus.com with details so we can investigate. Please do not exploit the issue or access data that is not yours.