Security & AI
Careful with your data, by design
How Videxa keeps each business’s data separate and protected, what Business AI may and may not do, and what the public demo does with what you enter.
How data is protected
These safeguards are built into Videxa today.
Every business kept separate
The server ties each request to one business, every query filters on it, and row-level security in PostgreSQL enforces it as a third layer.
Passwords stored safely
Passwords are hashed with PBKDF2-HMAC-SHA256 and 600,000 iterations. The password itself is never stored.
Secure sessions
Signing in sets an httpOnly, Secure cookie with a random token. Only a hash of it is kept, and a session ends after 14 days without use.
Protected requests
Changes are checked against cross-site request forgery, and signing in, the API and AI are rate limited.
Integration tokens sealed
Access tokens from connected tools are encrypted with AES-256-GCM. Connecting uses single-use state, with PKCE where the provider supports it.
Disconnect means gone
Disconnecting revokes the access token where the provider allows it, and deletes the data that came from that connection.
Private documents
Uploads are stored privately, their type is checked from the file itself, and downloading requires permission.
Audit log
Important actions are recorded in an append-only audit log.
Every number traceable
Figures and AI answers keep a link to the source they came from.
No trackers here
This website runs without cookies, analytics or third-party scripts.
What Business AI may and may not do
Every AI action goes through the same rules as the rest of the product. The model doesn’t decide what it’s allowed to do.
No AI vendor by default
Business AI starts as a built-in assistant that works without a language model. A server can be configured for Anthropic, Google Gemini, OpenAI or a local model; nothing goes to a provider until one is set up.
Where AI may run
Your policy can allow any connected provider, only EU-hosted or local models, or only local models.
What AI may receive
Choose which kinds of data outside providers may receive: financial, customer, document, marketing or website data.
| Read business data | Allowed |
|---|---|
| Create tasks | Approval required |
| Change financial data | Approval required |
| Change integrations | Approval required |
| Pay invoices | Not possible |
Reading still follows the user’s role: Business AI only sees what that person may see.
What the demo does with what you enter
- No account, password or real integrations needed.
- What you enter stays in this browser.
- All business data is simulated and labelled as demo data.
- The demo AI is a deterministic planner, not a language model.
- Resetting the demo deletes your demo workspace from this browser.
Not built yet
Worth knowing before you rely on Videxa. These are planned, but not there today:
- Two-factor authentication
- Single sign-on (SSO)
- Email verification and password reset
- Exporting or deleting your account yourself
- Backups stored away from the server
See what Videxa would flag for a business like yours
Describe a business and the demo builds a simulated version of it to explore.
No account needed