Trust & security
Alle's ClinXAi keeps provider credentials on the server, separates public product surfaces from internal workspaces, and keeps source boundaries visible.
1. Technical controls and boundaries
1.1 Server-side secrets
AI, search and OCR provider credentials are read from server environment variables and are not rendered into public HTML or browser JavaScript.
1.2 Internal workspaces
Internal workspace routes are disabled by default and require explicit server configuration to enable. Administrative APIs require authenticated server-side authorization.
1.3 Public abuse controls
Public Nova endpoints use request-size limits and rate limiting. Security headers restrict framing, browser permissions and unexpected cross-origin behavior.
1.4 Source boundaries
Controlled Nova knowledge, live web results, uploaded PDFs and image interpretation are labelled separately so provenance is not silently blended.
1.5 Account boundary
WordPress/WooCommerce remains the master identity source. Passwords stay with WordPress; the Accounts service and Alle's ClinXAi exchange only short-lived one-time authorization codes and a minimum internal user identifier. Application sessions use secure, HttpOnly, SameSite cookies and expire after eight hours.
2. Scope, identity and sessions
2.1 What this summary does and does not establish
This page describes controls in the current AI application and the intended boundary between public tools, accounts and internal workspaces. It is not an independent penetration-test report, an ISO or SOC certification, or a guarantee that the wider WordPress, payment, hosting and provider systems have identical controls. Security depends on the connected systems as well as this application.
2.2 Shared identity, separate permissions
Accounts uses the main WordPress identity to support sign-in to the AI site. A successful login authenticates an identity; it does not by itself grant administrator access, purchasing authority or access to another customer’s records. WooCommerce and WordPress enforce their own role and order permissions. The public Nova catalog connection retrieves products and document links and does not expose private checkout or customer data.
2.3 Session handling and shared devices
Application sessions use secure, HttpOnly, SameSite cookies on the HTTPS deployment. The AI session expires after eight hours; other connected services may have different session lifetimes. Each service maintains its own session. Do not assume that signing out of one site signs out every connected site. Browser-saved conversations and drafts are separate from authentication and can remain after sign-out; clear them before handing a shared device to another person.
3. Inputs and source handling
3.1 Input controls and external processing
Public requests are subject to size limits and rate limiting. Uploaded data is processed for the requested AI, extraction or image feature and may be sent to configured providers. File validation and limits do not turn a public chat into an approved repository for confidential or sensitive records. Redact unnecessary information and verify your organisation’s requirements before selecting a file.
3.2 Sources and untrusted material
Public pages, search results and uploaded files are evidence to review rather than authority to perform actions. Nova responses can include inaccurate interpretations or text from an untrusted source. Do not follow a source’s request to disclose credentials, pay an invoice, grant account access or execute instructions without independent verification. A legitimate-looking product link should still be checked for the expected host and document identity.
4. Reporting and user checks
4.1 How to report a vulnerability
Send care@allesclinx.com a concise description, the affected page or endpoint, the approximate time and steps that reproduce the issue using your own account and data. Redact passwords, tokens, personal records and provider secrets. Do not retrieve another user’s information, disrupt service, evade limits or publish exploit details before the issue can be investigated. This contact route does not authorise unrestricted testing or promise a bug-bounty payment.
4.2 Incident and account concerns
For an unexpected login, suspicious redirect or exposed information, stop the affected activity and contact support. Change compromised credentials through the main site’s account or recovery process and review the Google account if social sign-in is involved. We investigate relevant reports and address notifications where applicable law requires them. The timing and scope of a response depend on the incident; this page does not make an unverified 24-hour response or complete-prevention guarantee.
4.3 Checks users should make
Use the expected allesclinx.com, auth.allesclinx.com and ai.allesclinx.com addresses, keep browsers updated and avoid sharing access links. Check product and safety decisions against current published documents. Keep independent copies of approved operational records: a saved browser draft or AI reply is not a controlled compliance record or backup. Report a mismatch between this summary and observed behaviour so it can be reviewed.