Security

Built for trust from day one

AttneX handles sensitive compliance data and API credentials. Security isn't a feature — it's the foundation.

Your credentials and data, protected

Encrypted at rest

Every API key is encrypted the moment you enter it using Fernet symmetric encryption. Credentials are stored as scrambled text, decryptable only at runtime.

Multi-tenant isolation

Each location's data is scoped by store ID. No query can cross between customers — the same architecture banks and healthcare systems use. Sensitive fields such as employee pay are gated behind a separate role.

Compliance boundary

Only regulatory-required fields are sent to the state ledger. Business data — pricing, margins, vendor terms — is architecturally firewalled from compliance submissions.

OAuth authentication

Sign in with Google or Microsoft OAuth. JWT-based session management with secure token storage.

Cryptographic proof chain

SHA-256 chained audit records link every compliance action. Tamper-evident, exportable proof bundles for auditors and stakeholders.

AttneX is the operator's private tool

The state only sees what gets submitted through the normal regulatory API. AttneX helps operators verify accuracy before submission — it does not expose business data to regulators beyond what compliance requires.