Xeneural
SECURITY IN XEN

World-class security, inherited. Your company's control, managed.

Your data lives replicated across several regions, encrypted in transit and at rest, protected at the network edge and backed up continuously. Inside your company, XEN decides who sees, who does and who approves.

01

Before XEN

The infrastructure the brain runs on protects every organization's data alike, with no configuration on your side.

Inherited infrastructureReplicas · Edge · Encryption · Backups
02

Inside your company

XEN applies your roles: viewing, recording and approving are separate permissions per module and per person.

Managed controlRoles · Permissions · Approvals
03

In writing

A 99.9 % availability commitment, a data processing agreement and documentary support in audits.

Contractual commitmentSLA · DPA · Audit

Inherited

Replicas, protected edge, encryption, backups and point-in-time recovery.

Managed by XEN

Roles, permissions, action approval and a history of every decision.

Committed by contract

99.9 % availability, a data processing agreement and audit support.

WHAT PROTECTS YOUR DATA BEFORE XEN DOES ANYTHING?

The infrastructure every organization inherits.

XEN runs on world-class infrastructure. These seven protections exist for every company from day one and depend on no configuration on your side.

Region AReplica
Region BReplica
Region CReplica
Network edge
Encrypted traffic
Your team
Data lives in three regions at once; traffic enters through a protected edge and travels encrypted.
  1. Data replicated across several regions

    Every write is copied to more than one geographic region. If a region fails, another one answers without your team noticing.

  2. Protection at the network edge

    Traffic enters through a perimeter that absorbs denial-of-service attacks and filters malicious requests before they reach the brain.

  3. Encrypted traffic and storage

    Encryption in transit between your browser and XEN, and at rest in data and document storage.

  4. Continuous backups

    Data is backed up continuously, not once a night, and the copies live apart from the operation.

  5. Point-in-time recovery

    The organization is restored to the minute before a mistake, without losing the rest of the day's work.

  6. Monitored networks

    The network and its accesses are watched permanently; an anomaly is handled before it becomes an incident.

  7. Isolation per organization

    The scope of every query is resolved on the server from the session. No request crosses from one company to another.

WHAT DOES XENEURAL SIGN?

An availability commitment and the terms a large company requires.

Inherited security comes with written commitments for the organizations that need them.

99.9 %availability committed by contract
  • Contract with SLAAvailability, response times and responsibilities in writing.
  • Data processing agreementWhich data is processed, where, for what and with which guarantees.
  • Audit supportDocumentation and evidence for your organization's internal or external audit.
WHAT DOES XEN CONTROL INSIDE YOUR COMPANY?

Who sees, who does and who approves.

Viewing, recording and approving are separate permissions, per module and per person. Agents work with the permissions of the person who authorizes them, never with permissions of their own.

My companyMain
Permissions by roleWhat each role can view, record and approve.
Northstar Industries · Main
AdministrationCollections, payments and credit approval.
DSLMRC
Northstar Industries
Access by module
ModuleViewRecordApprove
Sales
Accounts
Logistics
Accounting
Human Resources
Agents inherit these permissions from the person who authorizes them.
WHO APPROVED WHAT?

Every action that matters carries a signature.

An agent proposes, a person approves and XEN executes. The three steps stay in the history with who, when and on which document, and are read with each role's permissions.

  • Agent, person and document in the same history.
  • Automatic actions are recorded too, with the rule that allowed them.
  • The history is read with permissions; nobody edits it.
History of an actionToday
  1. Purchasing agent proposedOC-0311 · 120 filters · Filtros del Norte
    10:47
  2. Mariana Rojas approvedWarehouse Lead · from Xeni
    10:53
  3. XEN issued the orderSent to the supplier · copy in Accounting
    10:53
Nobody edits the history; it is read with permissions.
CONTROL AT EVERY LAYER

Where is each access decided?

In three different places, and none of them depends on the browser.

Identity

The session is verified on the server on every request; the scope comes from it, not from what the client declares.

The browser does not decide the scope.

Authorization

Roles delimit what each person can view, record and approve in each module.

Viewing, recording and approving are different.

Approval

The actions that matter, whether an agent or a person proposes them, wait for whoever holds the approval permission.

Nothing important happens without a signature.
Security questions

What the IT area asks before signing.

Isolation, recovery, contract and history.