The core: PHOENIX Cloud · Technical
Security
How your site is kept apart from others, who can change it, and how access is controlled and logged.
Isolation
- One site, one database, one database user per company. Your records are never in the same database as another company’s.
- Separate files. Uploaded files and attachments sit in your site’s own folder.
Access to your site
- HTTPS everywhere. Every site, every page and every API call is encrypted in transit. Certificates are issued automatically, only for real customer sites.
- Your first user is a System Manager, not the built-in Administrator, so day-to-day work never runs with the all-powerful account.
- Roles and permissions decide who sees what, down to single fields. See Users and roles.
- Clients see only their own records on the portal. Factory names and prices never reach them.
- Activity log: who changed what and when.
How we change sites
- The set-up agent that creates and changes customer sites has no public address. Only the Hub can reach it, with a secret token, and it can only do a fixed list of jobs.
- Every job is logged in the Hub’s provisioning log.
- API keys are stored encrypted.
Demo sites
Demo companies have outgoing email switched off and are removed with all their data after 24 hours.
Found a problem?
If you think you have found a security issue, email hello@phnxtech.com with the details. Please do not test against other customers’ sites.
Related pages
-
Your own site and database
Every company gets its own private site, database and files. What is on your site and who can sign in to it.
-
How the core works
The Hub, your site and the set-up agent: what each part does, and what happens in the minutes after a new site is ordered.
-
Backups and recovery
Backups of your site are part of the service. When they are taken, where they are kept, and how a restore works.
Still have a question?
Ask the PHOENIX assistant in the chat at the bottom right, or send us a message. We reply within one business day.