Skip to Content
SecurityPolicies for review

Policies available for review

The four policies below are real, currently maintained AlignAI documents — not summaries drafted for this guide — and each directly addresses part of your ask. They’re the only policies included in this package; a broader internal policy set exists but isn’t included here because it doesn’t bear directly on what was requested. Full text of each is available on request via the vendor portal.

Access Control Policy

Access to AlignAI’s own systems is granted on a least-privilege basis — users receive only the access their role requires — and access rights are explicitly granted or revoked through a formal process rather than defaulting open. This is the policy underlying the RBAC/permission-scoping part of your ask, and is distinct from the customer-facing Okta SSO setup covered in Identity & access.

Cryptography Policy

Requires cryptographic risk to be formally assessed for data in processing and at rest, and that strong cryptography — aligned to NIST SP 800-57 — be applied wherever encryption is used, with documented key-management procedures. Customer and confidential data in storage or in transit over a public network must use current, vendor-recommended cipher configurations. See Encryption for how this applies to AlignAI’s hosting stack.

Data Management Policy

Classifies all company data and information systems by sensitivity and business criticality, with Confidential as the highest tier — access to Confidential data is restricted to specific employees or departments and can only be shared under an approved exception. The specific retention schedule and customer-termination data-return process are covered in the full policy.

Business Continuity & Disaster Recovery Plan

Covers business-critical IT systems, tested annually, and independently audited with no exceptions noted under AlignAI’s SOC 2 Type II examination. See Backup, retention, and disaster recovery for how this applies to AlignAI’s hosting infrastructure.

Last updated on