ASOneCLI Privacy Policy
ASOneCLI is an internal tool operated by Aligned Software. This policy explains what data it handles and how.
1. Scope
This policy covers ASOneCLI, a credential gateway that Aligned Software runs inside its own infrastructure to let its AI agents call third-party services without holding the underlying credentials. It applies to the hosted ASOneCLI service and to the data that passes through it.
ASOneCLI is not available to the public. It has no public sign-up, no customer accounts, and no external users. The only people who interact with it directly are Aligned Software personnel and contractors acting on Aligned Software's behalf ("operators").
This policy does not cover the alignedsoftware.com website itself, which is a set of static pages that collect no data, set no cookies, and run no analytics.
2. Data ASOneCLI handles
ASOneCLI handles the following categories of data:
- Credentials. API keys, access tokens, OAuth tokens, and similar secrets for third-party services that Aligned Software is authorized to use. Operators store these in ASOneCLI so that agents do not have to.
- Operator account details. The name, email address, and authentication details of operators who administer ASOneCLI.
- Agent configuration. The identity of each agent, the credentials it may use, and the list of hosts it is permitted to reach.
- Request metadata. For each request an agent sends through the gateway: timestamp, agent identity, destination host and path, HTTP method, response status, and whether the request was allowed or refused.
- Request content. The bodies of requests and responses pass through the gateway in order to be forwarded. They are not stored except where a specific request is logged for debugging or security review.
Content obtained from third-party services (for example, repository contents, messages, or documents returned by an API) passes through ASOneCLI to the requesting agent and is governed by the terms of the service that supplied it.
3. How the data is used
ASOneCLI uses data only to do its job:
- to attach the correct credential to an outbound request on behalf of an authorized agent;
- to enforce host access control lists and other policy;
- to authenticate operators and record their administrative actions;
- to log request metadata for operational monitoring, debugging, and security review.
Aligned Software does not use data handled by ASOneCLI for advertising, profiling, or training machine-learning models, and does not sell it.
4. Third-party services and OAuth
Where ASOneCLI connects to a third-party service through OAuth or a similar authorization flow, it requests only the scopes needed for the work the agent is meant to do. Tokens obtained this way are stored in the ASOneCLI vault, used solely to make requests to that service on Aligned Software's behalf, and are never shared with any other party.
Aligned Software's use of data obtained from third-party services complies with those services' developer and API terms. Where a service imposes additional restrictions on the use of its data, those restrictions apply.
Aligned Software can revoke any stored token at any time from within ASOneCLI, and the owner of a connected account can revoke access from the third-party service's side.
5. Storage and security
Credentials are encrypted at rest with AES-256-GCM and decrypted only in memory at the moment a request is forwarded. Agents receive placeholder values and never have access to real credentials. Operator access to the dashboard is authenticated, and administrative actions are logged.
ASOneCLI runs on infrastructure controlled by Aligned Software. Access to that infrastructure is limited to operators with a need for it.
6. Retention
Credentials are kept until an operator removes them or the related third-party authorization is revoked. Request metadata logs are kept for operational purposes and periodically purged. Request content, where logged for debugging, is deleted once the issue is resolved.
7. Sharing
Aligned Software does not share data handled by ASOneCLI with third parties, except:
- with the third-party service a request is addressed to, which is the purpose of the gateway;
- with infrastructure providers that host the service, under agreements that restrict their use of the data;
- when required by law or to protect the security of Aligned Software's systems.
8. Changes
Aligned Software may update this policy as ASOneCLI changes. The effective date at the top of this page reflects the current version.
9. Contact
Questions about this policy or about data handled by ASOneCLI go to contact@alignedsoftware.com.