Security

Security as
architecture.

At Vixera AI, security is a set of design constraints, not a marketing page. Every product in the ecosystem is built under the same rules — and where a product is still being built, those rules are decided before the first feature is.

Principles

Eight constraints.
Every product.

These are the rules our products are designed under. Where something is planned rather than shipped, we say so in plain words.

Encryption in transit
Traffic between you and Vixera AI products travels over encrypted connections. Data does not move between our systems and yours in the clear.
Secure authentication
Access to a Vixera AI product requires authentication — sessions are tied to a signed-in identity, and credentials are never stored in plain text.
Least-privilege permissions
Roles and permissions are scoped to what a person actually needs. In Vixera, a warehouse operator and an administrator see different systems — by design, not by convention.
Integration controls
Integrations are designed to be connected and revoked individually. One connection going away should never mean tearing down your whole account — each link stands, and falls, on its own.
OAuth over passwords
Where our products connect to outside services, they are designed to use scoped, revocable authorization — OAuth — rather than asking you to hand over a password to another system.
Financial data through regulated providers
Planned financial features in Praevion and Vixera One are designed to read account data through regulated providers such as Plaid. We do not ask for, and will not store, raw banking credentials.
Data isolation
Vixera is multi-tenant: each business's data lives in its own tenant, invisible to every other. The same constraint carries into everything we build — your data is partitioned from everyone else's, user by user.
User control and revocation
What is connected, what is shared and what is remembered stays under your control. Access you grant is access you can take back — and revocation is designed to take effect immediately, not on a support ticket's schedule.

What we do not claim

No badges we haven't earned.

You will not find compliance logos on this page. Vixera AI does not advertise certifications — SOC 2, ISO, or any other — until they have been achieved and can be independently verified. A badge that can't be checked is decoration, and decoration is not security. When an audit is completed, it will be announced here with the evidence to back it. Until then, the honest description of our posture is the one above: a set of architectural constraints, applied to every product. If you have a security question, or you've found something we should know about, we want to hear it — write to us.

See how Vixera One applies these rules — connected by permission