AlignAI Developer & Security Guide
Audience: enterprise technical, integration, and security reviewers evaluating or building against the AlignAI platform.
This guide has two independent tracks. Use whichever one matches what you’re doing — you don’t need to read both end to end.
For engineers building against the AlignAI API, MCP server, or third-party connectors. Authentication, REST endpoints, field rules, sample code, integrations, and environments.
Developer GuideFor security, compliance, and vendor-risk reviewers. Identity and SSO, SOC 2, platform architecture, data handling, and policy summaries.
Security & ComplianceDeveloper guide
| Section | Covers |
|---|---|
| Overview & getting started | What you can build against, and how to get a developer environment |
| Authentication & API keys | Bearer tokens, environment binding, key lifecycle, in-product Swagger |
| REST API | Conventions, use cases, object model, solutions |
| Writing data | Field rules and the gotchas that cause the most support tickets |
| Field configuration | Reading the field-config and mapping your data to it |
| Sample code | Pagination helper and the recommended write workflow |
| MCP server | Client setup, tool reference, example workflows |
| Third-party integrations | Integration plan, design principles, setup prerequisites |
| Field syncing | Two-way field and status sync with connected systems |
| Email & notifications | Template configuration per environment |
| Environments & sandbox | Base URLs, tokens, and field-config per environment |
Security & compliance
| Section | Covers |
|---|---|
| Identity & access | SSO pass-through, provisioning, and how API auth differs |
| SOC 2 & certifications | Report type, auditor, and criteria covered |
| Architecture & data handling | Platform stack, data flow, encryption, tenancy, BC/DR, subprocessors |
| Policies for review | The four policies included in this package |
| Vendor portal | Where to get the SOC 2 report and full policy text |
Last updated on