All docs

Docs / Security & data

How Amolfi protects your data

Amolfi uses your data to do the work you ask it to do, and nothing else. It does not sell, trade, or scrape your data.

Grounded, not generic

The AI is grounded on your own records — that’s what makes an answer about your business instead of a generic one. Your workspace is isolated from every other organization at the database layer, not just in the interface.

Agents propose, owners approve

Agents propose rather than act: anything that moves money or leaves your workspace waits for a named owner to approve it, and sensitive server actions append to an audit log as they happen.

Credentials and API keys are reached only through server endpoints and never touch the browser. Secrets, API keys, bank items, billing, audit logs, and signing requests all stay server-side.

Isolation

Your workspace is a sealed room. CRM, projects, finance, legal, and marketing run natively inside one boundary — not stitched across six vendors’ clouds. Every read and write is gated by membership at the database layer; deactivate a member and their access ends with them.

Governed AI

AI with a gate, not a free hand. Agents draft from the records they’re permitted to read; risk tiers and review gates sit before anything a client could see; approved actions leave receipts — sensitive fields stripped first.

Audit log

If it mattered, it’s in the log. Sensitive server actions append to an audit log as they happen — history is added to, not edited — with redaction at write time.

Roles and access

Six roles, drawn precisely. From owner to guest, each person sees exactly the work they need — with per-module overrides and item-level guest scoping on top.

Server-only secrets

Secrets never reach the browser. API keys, secrets, bank items, billing, audit logs, and signing requests are reached only through server endpoints that enforce their own checks.

One link, one job. Client intake forms, approvals, document signing, booking, creator delivery, and portal views — each link does the one thing it was made for, nothing else.

Transport and files

Hosting sends HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, and a report-only Content Security Policy on live responses. File download endpoints re-check workspace or conversation access and return short-lived signed URLs.

Integrations

Connections that prove themselves. Inbound webhooks verify provider signatures or HMAC tokens before anything is processed; outbound OAuth uses single-use, HMAC-bound state. Bank connections run through Plaid Link — credentials are entered with Plaid, never in Amolfi.

Reporting a vulnerability

Found something? Email security@amolfi.com directly.

Where to read more

The commitments above are contractual in the privacy policy and the terms:

Read how it actually works. Setup, security, and the model underneath — in plain language, no marketing in the way.