ElitePA
Security

Built around controlled access.

ElitePA separates assistant instructions, calendar actions, and email transport so no AI model directly executes an unverified calendar action.

Authorized contacts

An assistant may interact with an outside contact only after that contact appears in an authorized conversation involving the ElitePA customer and the assistant. This prevents ElitePA from being used as a cold-email system.

Calendar protection

Calendar providers connect using OAuth. Before a meeting is created, ElitePA rechecks the selected time to reduce double-booking risk.

Credential protection

Stored provider credentials and tokens are encrypted at rest using the application encryption key. Administrative and webhook endpoints require separate secrets.

Email controls

Outbound mail is authenticated through the ElitePA domain. Delivery, bounce, and complaint events are tracked so problem addresses can be handled safely.

Operational controls

Duplicate inbound messages are detected, background jobs can retry safely, account usage is metered, and failed jobs can be reviewed by ElitePA administration.

Responsible disclosure

Security concerns may be reported to security@elitepa.com.