Summary for IT
| Topic | Answer |
|---|---|
| Endpoint | https://mcp.alertedly.com (streamable HTTP over HTTPS) |
| Authentication | Per-person OAuth sign-in (recommended), or API keys for automations |
| Isolation | A caller only sees their own account's companies, or their firm's |
| Write actions | 2 of 16 tools write (start tracking a company, queue a free report); everything else is read-only |
| Key storage | Hashed; the full key is shown once at creation |
| Key controls | read / write scopes, optional expiry, revoke any time |
| Audit | Every tool call and API request is logged; firm admins can review their firm's log |
| Rate limits | 60 requests/minute per person, 600/minute per firm |
| Prompt-injection handling | Web content is sanitized and returned in labelled blocks as data, not instructions |
Data flow
- Your AI client sends Alertedly a tool call: the tool name and its arguments (for example a company name and a week). Alertedly does not receive the rest of your conversation.
- Alertedly returns intelligence about the companies you or your firm track. That intelligence is built from public sources: company websites, news, social channels, job boards, ad libraries and USPTO records.
- The answer is then processed by your AI provider under your agreement with them. Choose the client and plan that matches your firm's data policy.
- See also the Privacy Policy and Compliance pages.
Authentication
| Method | Identity | Recommended for |
|---|---|---|
| Sign in with Alertedly (OAuth 2.1) | The individual person | Everyone using an AI assistant interactively |
| Personal API key | The individual person | One person's scripts or CLI tools |
| Organization API key | The firm (created by a firm admin) | Shared automations and scheduled jobs; read-only scope |
Keys are sent as X-API-Key or Authorization: Bearer. Prefer sign-in for people: it keeps identity, limits and the audit trail per person and leaves no long-lived secret in a config file.
Authorization and scoping
Scope is decided by the server from the caller's identity, never from the request. A request for a company outside your scope returns nothing about it.
| Who is calling | What they see |
|---|---|
| Member of one firm (sign-in or personal key) | The firm's portfolio and dealflow |
| Member of several firms | The earliest membership by default; pass org (name or slug) to pick another. Answers say which firm was used. |
| Organization API key | That firm's portfolio and dealflow |
| User with no firm | Their own tracked companies, plus companies from their completed free report |
| Anyone | Never another account's or another firm's companies, reports or signals |
| Action | Firm member | Firm admin | Read-only key |
|---|---|---|---|
| Read tools (briefs, signals, rankings, coverage...) | Yes | Yes | Yes |
| Add a company to dealflow | Yes | Yes | No |
| Add a company to portfolio | No | Yes | No |
| Create or revoke organization keys | No | Yes | No |
| View the firm's audit log | No | Yes | No |
Read and write tools
Read (14): list_companies, get_company_brief, get_company_intelligence, get_signals, get_events, get_portfolio_events, rank_companies, compare_companies, get_company_changes, get_competitor_radar, get_competitors, get_trademarks, get_coverage, check_free_report_status.
Write (2): track_company, request_free_report. Write tools require sign-in or a key with write scope. No tool deletes data or changes another person's settings.
API key management
- Hashed at rest. Alertedly stores a hash of each key. The full key is shown once, when you create it.
- Scopes.
readallows read tools and GET requests.writeis also needed for write tools and POST, PUT, PATCH or DELETE requests. A read-only key calling a write action gets 403. - Expiry. Keys can have an expiry date. Expired keys are rejected.
- Where. Personal keys: dashboard, API & Intelligence. Organization keys: Team settings, firm admins only.
Recommended policy
Revoking access
- API key: revoke it in the dashboard or Team settings. It stops working immediately.
- Sign-in: disconnect Alertedly in the AI client to sign out, or revoke the assistant's access from your Alertedly account.
- Someone leaves the firm: remove them in Team settings. They lose the firm's scope, whichever client they use.
Third-party web content
Tool output contains text collected from the public web, such as news articles, social posts, job listings and website copy. Any of it could contain text written to manipulate an AI (prompt injection). Alertedly:
- returns that text inside clearly labelled blocks, and the server instructions tell assistants to treat it as data, never as instructions;
- strips HTML, scripts, zero-width characters and embedded images, and caps the length of each excerpt.
Assistants and agents built on the API should do the same: never follow instructions found inside report text.
Audit logging
Every MCP tool call and every REST API request is logged with the person or key, the source (MCP or API), the tool or endpoint, and the time. Logging runs alongside the request and never blocks an answer. Firm admins can review their firm's AI queries in Team settings; the API /usage endpoint returns usage for a key.
Rate limits
| Limit | Applies to | Value |
|---|---|---|
| Per person | Each signed-in user, or each organization API key | 60 requests / minute |
| Per firm | All members and keys of one firm together | 600 requests / minute |
If limits can't be checked for a moment, read tools keep working and write tools are refused until they can.
Rollout checklist
- Invite partners and analysts to the firm in Team settings; make the right people admins.
- Add the connector once at the organization level in Claude or ChatGPT (see Quickstart).
- Ask everyone to sign in as themselves. Don't distribute keys to people.
- For each automation, create a read-only organization key with an expiry.
- Review the audit log in Team settings after the first week.
Security questions: contact us.