Integration Security | AlphaSense
Integration Security
Your data remains yours
Layer AI capabilities on top of your firm’s data with simple, auditable integrations that ensure strict access control and industry-leading security.
Integration Security Overview
Access Control
Clients have full control over the data you upload into the AI platform.
View our Data Management Policy
Fine-grained access control is available for all available features and users’ access to the content.
Shared drive integrations support automatic permission mapping to mirror your organization access and sharing settings within AlphaSense.
We provide APIs for customers to control the access to the documents within AlphaSense.
Connectors
Integrate your files in seconds
Unify your data, your tools, and 500M+ premium external documents.
User Uploads
Data Retention
For trials, files uploaded to AlphaSense are stored during the active trial period and are then removed 30 days after the end of the trial.
Files are parsed and scanned for malware before being stored within the cloud project. Any files with detected malware or exceeding our size limits will have an error for upload.
Files uploaded will only be accessible to the user who uploaded them. Users can then opt to share these files with other users within their account through our sharing capability.
✔ Individual File Limit: The maximum file size allowed is 100 MB per file.
✔ Upload Session Limit: There is no cumulative size limit for a batch as long as it does not exceed 100 documents per upload and each document is within the 100 MB individual file limit.
✔ AlphaSense supports a diverse array of file formats, including: .txt, .html, .htm, .pdf, .doc, .docx, .ppt, .pptx, .xls, .xlsx, .msg, .eml, .csv, .xlsb, .xlsm, .one, .tsv, and .ods.
✔ We do not support image, audio, video file types, and any other files outside of the list above for upload.
Integration Security
Content Ingestion
✔ Integrated documents are encrypted in our secure S3 buckets. We also store metadata to improve retrieval quality.
✔ If a file is deleted or unshared in the source (e.g., Google Drive), it’s also removed from AlphaSense.
✔ You choose exactly which folders and files you want to sync using our Selective Sync feature.
✔ We use industry-standard OAuth 2.0 as the default method for user-level authentication.
✔ AlphaSense provides real-time monitoring of data ingestion, with a live summary of files being synced, skipped, or failed.
✔ Clients can generate detailed reports within AlphaSense to review and audit the ingestion process at any time.
✔ We mirror the source system’s permissions (e.g., Google Drive, SharePoint), so users only see documents they already have access to.
✔ Client admins can further manage content permissions within AlphaSense using individual, shared, and workspace connections.
✔ Clients can disconnect any integration at any time, immediately revoking the access token and stopping all data syncing.
✔ When an integration is removed, all associated data is automatically deleted from our system.
Frequently Asked Questions
Can users delete uploaded files?
Uploaded files are stored under users My Workspace -> Upload section. Users can delete those files from that section.
For Generative Search, users can delete uploaded files before submitting their first query. Once a query is submitted, the files cannot be deleted directly from the Gen Search session but will be temporarily removed when the session is ended.
How do LLMs interact with integrated files?
Generative AI functionalities use FileUpload utility for users to upload multiple files directly from a user’s local computer. On successful upload, users can then ask questions against the docs using the search box. For Generative Grid, the uploaded documents are automatically parsed for the predefined queries.
How are users notified if there’s an error with uploads?
Users will receive email notifications for upload errors, such as when the file size exceeds limits, the number of documents surpasses 100 in a day, or unsupported file types are submitted. These notifications detail the unprocessed files to keep users informed about the status of their uploads.
Do you store the actual documents or just metadata?
We store the actual content (encrypted in our secure S3 buckets) to enable fast and accurate searches. We also store metadata to improve retrieval quality. If a file is deleted or unshared in the source (e.g., Google Drive), it’s also removed from AlphaSense.
Can we choose what data to sync from a third-party source?
Yes, AlphaSense lets you choose exactly what data you want to sync using our Selective Sync feature.
You don’t have to sync everything - you can pick specific folders or files. The options may vary depending on the integration.
What type of authentication is used to connect to third-party platforms?
We use OAuth 2.0 as the default method for user-level authentication. For enterprise setups, we support service accounts and delegated access where applicable.
Who can configure integrations — admins or users?
- Individual connections can be set up by users.
- Workplace or Shared connections are typically managed by IT or admins, depending on the configuration.
Can customer or IT Admins monitor integration usage and revoke access?
Yes - AlphaSense provides real-time monitoring of data ingestion. You can see a live summary of files being synced, skipped, or failed. Customers and IT admins can also generate detailed reports to review and audit the ingestion process at any time.
How are user permissions and access controls enforced?
We mirror the source system’s permissions (e.g., Google Drive, SharePoint), so users only see documents they already have access to. This includes RBAC, ACLs, and other native models - ensuring secure, permission-respecting search across your organization.
How often are permission changes in the source system synced with your platform?
Permissions are synced regularly - typically every 15 minutes to 1 hour, depending on the integration. Some platforms like SharePoint may sync permission updates every 12 hours to reduce load and meet platform-specific limits.
How can access to a third-party integration be revoked?
You can disconnect any integration directly from the Integration Center in the platform. This will immediately revoke the access token and stop all data syncing.
What happens to the data once the integration is removed?
When an integration is removed, all associated data is automatically deleted from our system. The account is moved to a disconnected state.
Can we restrict integration to certain users or teams?
Yes. Integrations can be configured based on use case and content permissions.
- Individual Connection: Ideal for personal use, giving you full control over your files.
- Shared Connection: Ideal for file sharing, making files available to others with ease.
- Workplace Connection: Ideal for admins who need to manage files for the entire organization.
Integration security
How does AlphaSense handle sensitive data uploaded by the customer?
Customer-uploaded content is treated as customer data and handled in accordance with the customer agreement. Uploaded content is encrypted at rest and in transit, scoped to the customer's tenant, and subject to access controls configured by the customer. Customer content is not used to train AlphaSense's underlying language models or any third-party LLM.
Are uploaded files scanned for malware?
AlphaSense applies several controls to enhance the security of uploaded files:
- File integrity verification: Uploaded files are verified to identify and reject files attempting to disguise their true type with an incorrect extension.
- Content sanitization: Uploaded content is sanitized during processing to prevent execution of any embedded scripts or active content.
AlphaSense continuously monitors and updates its security protocols to protect customer data.
What file types are accepted by AlphaSense for upload?
AlphaSense accepts a wide range of file types for upload, including text documents (PDF, DOC, DOCX, TXT, HTML), spreadsheets (XLS, XLSX, CSV), presentations (PPT, PPTX), and email formats (MSG, EML). The current list of supported file types is documented in the AlphaSense Help Center and developer documentation.
Transform intelligence into advantage
Develop bold strategies, seize opportunities, and lead with clarity and confidence.