Skip to content

Meet Alto Security Policy

Last updated:

Protecting your workspace

Meet Alto processes business conversations, contact information, knowledge sources, and integration credentials. Our application includes controls designed to restrict access and protect the operations you authorize. This page describes those controls and how to contact us about a security concern.

Our Privacy Policy explains information use and deletion. Our Terms of Service govern use of the service. This page does not create a separate uptime guarantee, certification, or service-level agreement.

Account and workspace access

Meet Alto uses Clerk for authentication and organization membership. Application access controls distinguish workspace members, owners, and authorized administrators. Supported workspace operations check identity and organization context; certain billing and administrative operations require additional permissions.

Use separate accounts for each team member. Review invitations, roles, and connected applications regularly, and remove access when it is no longer needed. Use the strongest authentication options available for your account and secure the identity provider used to sign in.

Platform connections and credentials

Supported social connections use platform authorization mechanisms such as OAuth. Meet Alto uses the permissions granted to perform supported operations, and does not require you to give us your social-platform password.

Our application includes encryption mechanisms for supported integration credentials and encrypted object-upload paths. Security protections vary by data type and subsystem. We do not describe application-level encryption as end-to-end encryption: authorized application services must be able to process information to provide the features you request.

You can revoke a connected service through available Meet Alto controls or the provider's settings. Revocation prevents future authorized use of that connection; data deletion is a separate process described in the Privacy Policy.

For TikTok connections, the application requires a configured encryption key for credential handling and includes a staged cleanup process for account disconnection. That process stops further authorized effects, removes covered objects and records, and verifies completion before reporting deletion complete. A pending request is not proof of completed erasure. These application mechanisms do not themselves establish TikTok review approval or certify the security of every infrastructure component.

API and authorized AI applications

Where API or MCP access is enabled, authentication and authorization controls check credentials, workspace association, and applicable permissions. Grant only the access an application needs. Treat API keys as secrets and revoke unused or compromised credentials promptly.

Applications and AI assistants you authorize may obtain information or perform actions allowed by their access. Review their privacy and security practices before connecting them. Revocation does not retrieve information already copied to an external application.

AI and automation safeguards

Meet Alto separates AI-generated proposals from backend checks that authorize supported actions. These checks can include connection status, recipient eligibility, platform restrictions, and configured permissions. Supported workflows also include controls intended to reduce duplicate delivery and reject untrusted instructions from retrieved content.

AI and automated safeguards can fail or produce incorrect results. Review business instructions, test automations, and monitor outcomes. Avoid placing secrets or unnecessary sensitive information in prompts, knowledge sources, test conversations, or uploaded files. Pause an automation if it behaves unexpectedly.

Application protections and diagnostics

The application includes signature validation for supported provider webhooks, request validation, scoped data access, and rate controls on supported routes. File and media workflows include size or type restrictions and controlled retrieval where applicable.

Operational records help diagnose failures and investigate suspicious activity. AI-generation telemetry is designed to record performance metadata without raw prompts or generated responses in those events. Other support or application records may contain personal information; they should be used only for authorized purposes.

Meet Alto relies on external infrastructure, authentication, storage, payment, and AI providers. A provider's security certification does not automatically certify Meet Alto. Ask us for evidence relevant to your requirements before relying on a particular certification, audit, hosting region, recovery objective, or contractual security commitment.

Reporting a vulnerability or incident

Email hey@meetalto.ai with the subject Security report. Include the affected URL or feature, a concise description, reproduction steps using your own account, and the potential impact. Remove secrets and other people's personal information from attachments. If sensitive evidence is necessary, ask us to arrange an appropriate transfer method first.

Do not access or modify another person's data, disrupt the service, conduct denial-of-service testing, attempt social engineering, or publicly disclose sensitive exploit details while reporting. Stop testing if you encounter information you are not authorized to access. This policy does not grant general permission to conduct penetration tests and does not promise a bounty.

We review reported concerns, investigate relevant evidence, and take appropriate containment or remediation steps. When a personal-data incident requires notification, we notify affected customers, individuals, or authorities as required by applicable law and our agreements. This page does not promise a fixed response time or that every service issue is a personal-data breach.

If you suspect your account is compromised, secure your sign-in account, revoke affected connections or API keys where possible, and contact us promptly. Do not send passwords or complete API tokens in a support message.

Scope and updates

No service can guarantee absolute security. This page summarizes selected application controls and does not certify every deployment setting or customer configuration. We update it as our service and verified practices change. Written security terms agreed with your organization take precedence on the matters they address.

BTMK Holdings LLC, doing business as Meet Alto
8 The Green, Suite R, Dover, Delaware 19901, United States
Email: hey@meetalto.ai