Built around controlled access.
ElitePA separates assistant instructions, calendar actions, and email transport so no AI model directly executes an unverified calendar action.
Authorized contacts
An assistant may interact with an outside contact only after that contact appears in an authorized conversation involving the ElitePA customer and the assistant. This prevents ElitePA from being used as a cold-email system.
Calendar protection
Calendar providers connect using OAuth. Before a meeting is created, ElitePA rechecks the selected time to reduce double-booking risk.
Credential protection
Stored provider credentials and tokens are encrypted at rest using the application encryption key. Administrative and webhook endpoints require separate secrets.
Email controls
Outbound mail is authenticated through the ElitePA domain. Delivery, bounce, and complaint events are tracked so problem addresses can be handled safely.
Operational controls
Duplicate inbound messages are detected, background jobs can retry safely, account usage is metered, and failed jobs can be reviewed by ElitePA administration.
Responsible disclosure
Security concerns may be reported to security@elitepa.com.