Access control
6-level RBAC with organization scoping enforces least-privilege access across every workspace action.
Security
Anchrix is designed for operational integrity with role boundaries, policy evidence, immutable audit trails, and encryption at every layer.
Core controls that protect every operation in the Anchrix platform.
6-level RBAC with organization scoping enforces least-privilege access across every workspace action.
Policy snapshots, deterministic evaluation records, and frozen evidence ensure reproducible compliance decisions.
Append-only event history with DB-trigger enforcement prevents tampering and supports regulator-ready exports.
TLS 1.3 in transit, AES-256 at rest. Secrets are managed through environment-scoped vaults, never stored in code.
Platform-level safeguards that protect data and availability.
Workloads run in containerized environments with network segmentation.
All data at rest is encrypted with AES-256. Backups are encrypted and geo-redundant.
Firewalled ingress, private subnets, and TLS-only communication between services.
Environment-scoped vaults with rotation policies. No secrets in source code or logs.
Real-time anomaly detection, structured logging, and automated incident escalation.
Edge-level traffic filtering and rate limiting protect all public endpoints.
Built-in controls that support regulatory and operational review.
Every API request and data query is scoped by organization identifier, preventing cross-tenant data access.
Critical operations require dual approval. The same actor cannot both initiate and approve a payout batch.
Database triggers enforce append-only semantics on audit events. No user or API can delete or modify historical records.
Policy evaluation context, routing decisions, and disposition rationale are frozen at decision time for audit replay.
Our coordinated process for handling security reports.
Send findings to security@anchrix.com with reproduction steps and impact assessment.
We confirm receipt within 2 business days and assign a tracking identifier.
Our team triages, reproduces, and assesses severity following industry frameworks.
Fixes are developed, tested, and deployed. Reporter is notified of resolution.
Security disclosure
We welcome responsible disclosures. Report findings to security@anchrix.com with reproduction steps and impact assessment.