Arxx

Your customer’s data never sees another customer’s side

That’s not a policy we promise to follow — it’s enforced on every single request, automatically, whether or not anyone remembers to check.

POST/v1/authz/check
principalusr_8f2a41c7
actiondocuments:read
resourcedoc://acme/invoice/1042
ALLOW
matchedrole:editor → documents:read
tenantacme · isolated
policyrbac_allow (v14)

Machine identity, verified

Every service proves who it is with a short-lived certificate issued per workload — not a shared API key that can leak, get copied, or outlive the person who created it.

Secrets held apart from everything else

Passwords, keys, and technical credentials live in a dedicated vault, never in our own application database — released only to the one workload authorized to read them, for only as long as it needs them.

Rules you can actually review

Every access rule is a reviewable policy evaluated on every request against your customer’s own rules — not a global switch that's either on or off for everyone.

A full record, always

Every decision, every role change, every credential issued is logged and queryable — the evidence exists before anyone asks for it.

The guarantee comes first: one customer's data, secrets, and permissions are never visible to another — not through a shared database row, not through a support tool, not through a debugging session. This is checked on every request, not audited after the fact.

Underneath that guarantee: machine identity is verified through short-lived certificates issued per service rather than long-lived shared keys, and every authorization decision is evaluated against your customer's own rules at request time, not against a single global ruleset everyone shares.

Secrets are never stored in our own application database — they are held in a dedicated secrets backend and released only to the workload that is authorized to read them, for exactly as long as it needs them.