Security
Encrypted. Scoped.
Logged.
The controls that keep your business — and your clients’ data — safe. Everything below is live in the product today, and you can see it for yourself.
Live in the product today You stay in control
Encryption
Your secrets, encrypted — and never in the open.
Every credential and API key you store is encrypted with AES-256-GCM before it touches the database, and decrypted only when it’s needed. Traffic to and from CNEX-Flow is protected with TLS.
AES-256-GCM at rest
Authenticated, industry-standard encryption for every stored credential and secret.
Out of your code
Credentials live in an encrypted vault — never hard-coded or sitting in plain config.
Protected in transit
Every connection to CNEX-Flow is encrypted with TLS.
Layered protection
Getting in is the hard part — for everyone but you.
We’ve carried the weight of keeping your business safe, so you don’t have to. A few of the many protections built into CNEX-Flow.
More than a password
Add a second step — an authenticator app, a text or email — and we’ll ask for it whenever you sign in somewhere new.
It locks itself
Too many failed attempts and your account quietly locks for a while. No one has to notice, and no one has to fix it.
You’ll know right away
The first sign-in from a new device sends you an email — with the device, and roughly where it was.
Bots stay out
Automated attacks are turned away before they reach your sign-in, so the only one trying to get in is you.
Even we can’t read it
Your password is turned into something unreadable before it’s stored — one way only, with no version we could ever undo.
Every sign-in, on the record
Each one is logged — the device, the place, the moment — so nothing touches your account in the dark.
Access control
Everyone sees exactly what they should. In layers.
Permissions stack from the whole organization down to a single person — so access is least-privilege by default, and you grant exactly what’s needed, no more.
Permissions stack, broad → specific
- 1OrganizationThe baseline everyone starts from.
- 2AdminsElevated, minus owner-only actions.
- 3Job rolesPermissions by what someone does.
- 4DivisionsScoped per team or client — with inheritance.
- 5GroupsCross-cutting sets of people.
- 6IndividualFine-grained, per person.
A member’s effective permissions — every row traced to where it’s granted or denied.
Least-privilege by default
New members start with the minimum, and you add from there.
Four-eyes approval
Sensitive actions can require a second admin to sign off before they run.
Every organization isolated
One organization’s data is walled off from every other — enforced on every request.

Your AI, scoped
Your AI is scoped like a teammate — not a master key.
Connekz works inside the same permissions as the person directing it. It only reaches the data, tools and credentials in its lane — and it’s checked before it acts.
It inherits your permissions
The AI sees what you’d see — never more.
Scoped credentials
It can only pull secrets for the organization and project it’s working on.
Checked before it acts
Every action is permission-gated. Denied means denied.
Audit & ownership
Everything’s on the record. And your data stays yours.
On the record
- Logins, permission changes and approvals are all logged.
- Permission changes capture the before and after.
- The log can’t be quietly edited after the fact.
Yours to keep — or take
- Delete your account, or your whole organization, whenever you want.
- Export your data and your chat history.
- A 30-day recycle bin catches mistakes before they’re gone.

Ready when
you are.
Hand Connekz the busywork — and give your people back the work they actually love.
- 30-day free trial
- Cancel anytime