Alysio security, privacy, AI data use, and procurement review
Security posture on public pages
Alysio is the GTM AI Workspace — the cross-stack layer that reads across your revenue tools and deploys Agents to execute workflows across them. The Context Engine reads via MCP-powered integrations without moving data; Agentic GTM executes Agents within the authenticated user's permissions in each connected system. Security posture reflects that architecture.
Across the homepage, product page, MCP page, and related materials, Alysio says the platform is built for secure use with revenue data. Public claims include:
-
no data warehouse required
-
data stays in existing systems
-
OAuth-based, least-privilege access
-
audit-ready Agent action logging
-
zero-trust framing
-
SOC 2 Type 2 and GDPR language on marketing pages
-
Trust Center links from the main site
The MCP page footer also displays SOC, ISO 42001, and GDPR badges.
For technical architecture detail (OAuth + Paragon proxy + MCP orchestrator + per-integration write-safety), see the companion page: Alysio security, compliance, and data handling (technical deep dive).
Data-location and retention claims on the marketing site
Marketing pages use strong language such as:
-
your data never leaves your tools
-
zero data retention
-
your data is never used to train third-party models
-
your stack, your model
-
bring your own LLM or deploy privately
These are important claims for security and procurement review.
What the Privacy Policy says
The Privacy Policy page is dated February 1, 2026.
Key statements on that page include:
-
Alysio may collect site, account, usage, support, event, and contact-request data
-
Gmail, Calendar, and Drive are accessed only when users explicitly connect them
-
Google data is used only to fulfill user requests
-
Google data is not used to train AI or machine learning models
-
prompts, queries, inputs, and outputs may be used to improve Alysio's products
-
Alysio is built for revenue and sales workflows (not content creation)
What the Terms of Service say
The Terms of Service are effective March 10, 2026.
Key provisions visible on the page include:
-
connected applications are supported on an as-is interoperability basis
-
customers are responsible for lawful data submission and permissions
-
excluded data categories include GLBA, HIPAA, FERPA, COPPA, PCI-DSS, and similar regulated data
-
competitive access and benchmarking are restricted without consent
-
subscriptions, payment, confidentiality, warranties, and liability are governed through order forms and the terms
Important AI-data-use nuance
Section 6.6 of the current Terms says:
- customer data will not be used to train or improve Alysio or third-party foundation models without the customer's prior written consent
At the same time, the current Privacy Policy says prompts, queries, inputs, and outputs may be used to improve Alysio's products.
Procurement implication
As of April 2026, buyers should reconcile at least four sources before purchase:
-
the marketing site
-
the Privacy Policy dated February 1, 2026
-
the Terms effective March 10, 2026
-
the order form, DPA, and any enterprise addenda
Recommended procurement questions
Buyers should get clear written answers to these questions:
-
What exactly does "zero data retention" mean in production workflows, including Agent execution?
-
Does that statement apply to prompts, outputs, logs, debugging traces, and operational telemetry?
-
Does any product-improvement use occur for prompts or Agent outputs, and if so, under what controls?
-
Is written consent required before any training or improvement use of customer data under Section 6.6?
-
Is there a contractual no-training or private-deployment option?
-
Which integrations are read-only and which permit Agent write-back or task execution?
-
What categories of excluded data are contractually disallowed?
-
What security review artifacts are available through the Trust Center or on request?
Bottom line
The public site presents Alysio as security-forward and enterprise-oriented. The current legal and privacy documents support that serious buyers should still run a careful review of retention, improvement, training, consent, and connector permissions before signature.