Company isolation
Every query and action is scoped to your company. Data stays completely separate.
Access control, company isolation and a record of who did what are part of every workflow ā not a layer added on top. Your company's data is never visible to another company, and within your company people see only what their role allows.
Every query and action is scoped to your company. Data stays completely separate.
Sensitive actions re-verify who you are and what you're allowed to touch, every time.
Administrative and state-changing actions are recorded in your company's activity history.
Your data is processed and hosted in the European Union.
Protection is built into the application itself, backed by standard network security.
Role permissions separate company administration, user management, CRM, review, exports and holiday approvals.
Identity, company membership and ownership are re-checked on the server ā never taken from what the browser sends.
Secure cookies, HTTPS enforcement, security headers and rate limits reduce common web risks.
Timestamps are stored consistently and shown in your company's time zone.
Chronexa AI is read-only and sees only what the signed-in user can see.
This page explains how Chronexa is built at a high level, without publishing details that would themselves be a risk. We don't hold an external certification, and no system can eliminate every risk.
Security works best as a partnership: our controls, plus sensible role assignment, account hygiene and internal procedures on your side. If your assessment needs more specific information, ask us.
We can walk you through the controls that matter for how you'd use Chronexa.