Skip to content

Security

Security at AltOne

Publishers and universities trust us with unpublished books and course material. This is how we look after it.

  • Never used for training

    Images go to our AI providers only to draft descriptions, under terms that exclude training.

  • Strong sign-in

    Two-step verification, single sign-on, and limits on repeated attempts.

  • Least access

    Roles for every job, and people outside a project can’t even see that it exists.

  • Yours to take or delete

    Export your data, or delete your account, whenever you like.

01Accounts and sign-in

  • Passwords are stored only as salted hashes (bcrypt); nobody at AltOne can read them.
  • Two-step verification with an authenticator app, single-use recovery codes, and protection against a code being replayed.
  • Sign in with Google or Microsoft. An account is linked only to an email address the provider has verified.
  • Repeated failed sign-ins are limited per address and per account.
  • You can sign out of every other device at any time, and changing your password does it for you.

02Access and permissions

  • Organisations have owners, administrators, managers, editors, reviewers, viewers and billing members; projects add their own roles.
  • Someone who isn’t a member of a project or organisation gets “not found”, so its existence isn’t revealed.
  • API keys are stored hashed, can be read-only or read-and-write, and can expire.
  • An audit log records who changed what, including sign-in, sharing, billing and data exports.

03Your content and AI

Images, and the text around them, are sent to our AI providers only to draft and translate descriptions, under API terms that exclude training on that data. We don’t train models on your content either. The providers are listed in our Privacy Policy.

Every description is a draft until a person in your organisation approves it.

04The application

  • All traffic is encrypted with HTTPS, and browsers are told to use nothing else (HSTS).
  • Security headers on every response stop browsers guessing file types, keep other sites from framing AltOne (except the pages your LMS opens inside a course), and limit what is shared with other sites.
  • Requests that change data are refused when they come from another website with your session.
  • Uploaded archives and documents are checked for size and for decompression bombs before they’re opened.
  • Links you import from are fetched with protection against reaching private networks.
  • Error reports are cleaned of passwords, keys and tokens before they’re stored.

05Payments

Payments are handled by Razorpay. Card and bank details go straight to Razorpay; we never see or store them.

06Your data

  • Download your files with the approved descriptions at any time.
  • Request a copy of your personal data from Settings, and delete your account yourself.
  • Uploads that are never imported are deleted automatically.

07Reporting a security issue

If you think you’ve found a vulnerability, email support@nexorityinfotech.com with “Security” in the subject and as much detail as you can. Please give us a reasonable time to fix it before sharing it, and don’t access other people’s data while testing. We’ll reply to let you know we’re on it.