Security

Encrypted. Scoped.
Logged.

The controls that keep your business — and your clients’ data — safe. Everything below is live in the product today, and you can see it for yourself.

Live in the product today You stay in control

Encryption

Your secrets, encrypted — and never in the open.

Every credential and API key you store is encrypted with AES-256-GCM before it touches the database, and decrypted only when it’s needed. Traffic to and from CNEX-Flow is protected with TLS.

AES-256-GCM at rest

Authenticated, industry-standard encryption for every stored credential and secret.

Out of your code

Credentials live in an encrypted vault — never hard-coded or sitting in plain config.

Protected in transit

Every connection to CNEX-Flow is encrypted with TLS.

Layered protection

Getting in is the hard part — for everyone but you.

We’ve carried the weight of keeping your business safe, so you don’t have to. A few of the many protections built into CNEX-Flow.

More than a password

Add a second step — an authenticator app, a text or email — and we’ll ask for it whenever you sign in somewhere new.

It locks itself

Too many failed attempts and your account quietly locks for a while. No one has to notice, and no one has to fix it.

You’ll know right away

The first sign-in from a new device sends you an email — with the device, and roughly where it was.

Bots stay out

Automated attacks are turned away before they reach your sign-in, so the only one trying to get in is you.

Even we can’t read it

Your password is turned into something unreadable before it’s stored — one way only, with no version we could ever undo.

Every sign-in, on the record

Each one is logged — the device, the place, the moment — so nothing touches your account in the dark.

Access control

Everyone sees exactly what they should. In layers.

Permissions stack from the whole organization down to a single person — so access is least-privilege by default, and you grant exactly what’s needed, no more.

Permissions stack, broad → specific

  1. 1OrganizationThe baseline everyone starts from.
  2. 2AdminsElevated, minus owner-only actions.
  3. 3Job rolesPermissions by what someone does.
  4. 4DivisionsScoped per team or client — with inheritance.
  5. 5GroupsCross-cutting sets of people.
  6. 6IndividualFine-grained, per person.

A member’s effective permissions — every row traced to where it’s granted or denied.

Least-privilege by default

New members start with the minimum, and you add from there.

Four-eyes approval

Sensitive actions can require a second admin to sign off before they run.

Every organization isolated

One organization’s data is walled off from every other — enforced on every request.

Connekz

Your AI, scoped

Your AI is scoped like a teammate — not a master key.

Connekz works inside the same permissions as the person directing it. It only reaches the data, tools and credentials in its lane — and it’s checked before it acts.

It inherits your permissions

The AI sees what you’d see — never more.

Scoped credentials

It can only pull secrets for the organization and project it’s working on.

Checked before it acts

Every action is permission-gated. Denied means denied.

Audit & ownership

Everything’s on the record. And your data stays yours.

On the record

  • Logins, permission changes and approvals are all logged.
  • Permission changes capture the before and after.
  • The log can’t be quietly edited after the fact.

Yours to keep — or take

  • Delete your account, or your whole organization, whenever you want.
  • Export your data and your chat history.
  • A 30-day recycle bin catches mistakes before they’re gone.
Connekz

Ready when
you are.

Hand Connekz the busywork — and give your people back the work they actually love.

  • 30-day free trial
  • Cancel anytime
Or talk to the team
Re-watch Connekz ship a PR