Security
Security and compliance
thexsys holds other companies’ books. Here is what protects them, stated as plainly as we can — including what is not true yet.
Tenant isolation
Every business table carries a tenant id enforced by PostgreSQL row-level security, not just application code — a query without tenant context returns zero rows at the database, even from a bug (ADR-0004). Platform staff, partners and tenant users hold separate identities and token audiences (ADR-0005), so a leaked tenant token cannot reach the operator console and a leaked staff token cannot reach tenant data.
Immutable audit log
Every business mutation is written to a hash-chained audit log: each row carries the hash of the row before it, so an attempt to edit or delete history breaks the chain and is detectable by recomputation, not by trust.
MFA and account protection
Two-factor authentication (TOTP), lockout after repeated failed sign-ins, device session lists a user can review and revoke, and a password policy enforced at sign-up and reset.
Encryption
Secrets (API keys, webhook signing secrets, integration credentials) are hashed or encrypted at rest and never logged in full; connections use TLS in transit.
Backups and restore drills
Daily verified backups with a 15-minute recovery point objective and a 2-hour recovery time objective as targets, and scheduled restore drills that prove a backup actually restores, not just that it was written.
Security events
Sign-ins, failures, lockouts, MFA changes, password resets, session revocations, API-key creation and any support access to a tenant are all recorded as security events a tenant can review from their own workspace.
SOC 2 Type I readiness
We are working toward SOC 2 Type I on the Security, Availability and Confidentiality criteria — not certified yet, and we say so plainly rather than imply otherwise. The full control matrix, with what is implemented, partial or planned, is a living internal document; a summary is available on request.
Data residency
Production is planned for Google Cloud’s Doha region as the primary GCC location, with tenant data pinned to its assigned region and never moved without written agreement. Today, pre-launch, all data runs on a single encrypted development database in Doha, Qatar. See the full data residency statement for what is and is not promised yet.
Responsible disclosure
Found a way in that should not exist? Email security@thexsys.com with what you found and how to reproduce it. We acknowledge within 2 working days, assess severity within 5, and credit reporters who want credit. Full scope and rules of engagement are in SECURITY.md.
Request the security package
For a due-diligence review, we can share the full control matrix, our policies and our latest restore-drill record under a mutual NDA.