Skip to content

Security & AI

Careful with your data, by design

How Videxa keeps each business’s data separate and protected, what Business AI may and may not do, and what the public demo does with what you enter.

How data is protected

These safeguards are built into Videxa today.

  • Every business kept separate

    The server ties each request to one business, every query filters on it, and row-level security in PostgreSQL enforces it as a third layer.

  • Passwords stored safely

    Passwords are hashed with PBKDF2-HMAC-SHA256 and 600,000 iterations. The password itself is never stored.

  • Secure sessions

    Signing in sets an httpOnly, Secure cookie with a random token. Only a hash of it is kept, and a session ends after 14 days without use.

  • Protected requests

    Changes are checked against cross-site request forgery, and signing in, the API and AI are rate limited.

  • Integration tokens sealed

    Access tokens from connected tools are encrypted with AES-256-GCM. Connecting uses single-use state, with PKCE where the provider supports it.

  • Disconnect means gone

    Disconnecting revokes the access token where the provider allows it, and deletes the data that came from that connection.

  • Private documents

    Uploads are stored privately, their type is checked from the file itself, and downloading requires permission.

  • Audit log

    Important actions are recorded in an append-only audit log.

  • Every number traceable

    Figures and AI answers keep a link to the source they came from.

  • No trackers here

    This website runs without cookies, analytics or third-party scripts.

What Business AI may and may not do

Every AI action goes through the same rules as the rest of the product. The model doesn’t decide what it’s allowed to do.

  • No AI vendor by default

    Business AI starts as a built-in assistant that works without a language model. A server can be configured for Anthropic, Google Gemini, OpenAI or a local model; nothing goes to a provider until one is set up.

  • Where AI may run

    Your policy can allow any connected provider, only EU-hosted or local models, or only local models.

  • What AI may receive

    Choose which kinds of data outside providers may receive: financial, customer, document, marketing or website data.

Default AI policyAs set for every new business
Read business dataAllowed
Create tasksApproval required
Change financial dataApproval required
Change integrationsApproval required
Pay invoicesNot possible

Reading still follows the user’s role: Business AI only sees what that person may see.

What the demo does with what you enter

  • No account, password or real integrations needed.
  • What you enter stays in this browser.
  • All business data is simulated and labelled as demo data.
  • The demo AI is a deterministic planner, not a language model.
  • Resetting the demo deletes your demo workspace from this browser.

Not built yet

Worth knowing before you rely on Videxa. These are planned, but not there today:

  • Two-factor authentication
  • Single sign-on (SSO)
  • Email verification and password reset
  • Exporting or deleting your account yourself
  • Backups stored away from the server

See what Videxa would flag for a business like yours

Describe a business and the demo builds a simulated version of it to explore.

No account needed