Infrastructure security overview

Security that keeps your AI employees and data in Canada

AlloTech.AI runs on a modern SaaS stack built for Quebec and Canadian SMBs. TLS 1.3 in transit, AES-256 at rest, isolated tenant networks, RBAC, approval gates by default, and optional full self-hosting.

Security foundations

🔐

Encryption in transit and at rest

Every connection uses TLS 1.3 with HSTS. Data at rest in PostgreSQL, Redis, and Qdrant is encrypted with AES-256. Backups are encrypted with a separate key before leaving the server.

🛡️

Isolated tenant networks

Each customer runs in logically separated containers connected through isolated Docker networks. One tenant cannot access another tenant's data, memory, or vector store.

👤

RBAC and least privilege

Role-based access control, secure authentication, API-key scoping, and optional mandatory MFA for Enterprise accounts. Administrators control exactly what each AI employee can read or write.

🛑

Approval gates by default

Real-world actions stop at an approval gate until a human validates them. Full autonomous mode is opt-in, per employee. Every approval and rejection is written to an immutable audit log.

Hosting and deployment options

Keep data in Canada by default, or run everything on your own infrastructure.

Canadian SaaS hosting

By default, the FastAPI backend, Next.js frontend, PostgreSQL, Redis, and Qdrant vector store are hosted on Canadian infrastructure. No cross-border data transfer occurs by default. Default LLM providers are Kimi (Moonshot) and Ollama.

Enterprise self-hosting

For Enterprise customers, we deploy inside your environment with Ollama for local inference. Your data never leaves your network, giving you full sovereignty and simplified Law 25 compliance.

Reason → gate → act

The loop every AI employee follows. This is why you can let an agent propose work without worrying it will act on its own.

1. Reason

The employee analyzes the request, searches its memory and your RAG documents, and decides which action to propose. Zero real-world effect at this step.

2. Gate

The proposed action stops. You see what the employee intends to do, why, and on which data. Approve, modify, or refuse in one click.

3. Act

Once approved, the action executes and is logged in the audit trail — full traceability for compliance and incident review.

Vulnerability management and compliance

Security is a continuous process, not a one-time checklist.

🔍

Regular assessments

We run vulnerability scans, dependency checks, and code reviews. Security patches are prioritized and deployed quickly.

📋

Audit-ready logs

Account administrators can export audit logs and compliance reports. Enterprise customers can request security attestations.

⚖️

Law 25 built in

Incident register, data inventory, consent tracking, and breach notification workflows are included in every plan.

🌐

No cross-border by default

Personal data stays in Canada unless you explicitly configure a third-party LLM provider. You control which providers are active.

Ready to deploy a secure AI employee?

Start free for 7 days, or talk to us about a sovereign Enterprise deployment.