Security & trust

Built for teams that collect
sensitive documents and PII.

Xenqu is built to safeguard the personal information and sensitive documents your workflows depend on. Layered controls protect data from upload through retention, while clear records help your team demonstrate responsible handling.

Security at a glance
Platform controls

How customer data is protected as it moves through Xenqu.

Security and privacy are built into the way Xenqu stores, processes, and shares customer data. Account isolation, identity-based access, and encryption work together to keep information with the right organization and the right people.

Tenant isolation

Each customer account is separated from the others. Access is checked against the signed-in account before customer data is read or changed.

Identity-based access

Standards-based sign-in ties every session and API request to an authenticated user in the correct customer account.

Encryption in transit

TLS protects data moving between users and Xenqu. Traffic between Xenqu services stays on secured cloud networks.

Encryption at rest

Databases and file storage are encrypted at rest. Additional field-level encryption can protect keys used to verify tamper-evident records.

Sensitive documents

Protection starts the moment a document arrives.

Government IDs, tax forms, certificates, and other sensitive evidence deserve more than ordinary attachment handling. Xenqu separates, scans, and controls uploaded files before they enter a workflow.

Separated before use

New uploads are held in a quarantine area and cannot be attached to a case until they pass the required checks.

Scanned and verified

Each upload is fingerprinted, checked for duplicates within the account, scanned, and optionally checked for format before it becomes available.

Retention controls

Your organization can set retention periods for customer data. Uploaded files are removed when they reach the end of that period.

Auditability

A record your organization can stand behind.

Xenqu keeps the request, response, correction, and approval connected to the case. Your team can show what happened and, when stronger proof is required, verify that critical submitted data has not changed.

Complete activity history

Outreach, replies, delivery events, and administrative actions are recorded as they happen, creating a clear history of each case.

Tamper-evident records

Forms that require stronger proof can preserve a verifiable snapshot of submitted data with a hash, signature, and timestamp.

Controlled workflow changes

Published workflows remain stable. Later changes create a new version, while cases already in progress keep the rules they started with.

Evidence in context

A clear record from outcome back to activity.

The case overview keeps the result, timing, summary, and chronological record together so reviewers can understand what happened without piecing it together from separate systems.

Xenqu case overview report showing outcome and activity history
The focused report view keeps the outcome and its supporting record together.
AI processing

Xena stays inside your account boundary.

Xena works with data in your Xenqu account. She does not browse the open web or reach systems outside Xenqu-except disclosed AI and messaging providers, and opt-in partners you enable.

When she builds a workflow, assesses an upload, or coordinates follow-up, she sends only the prompt and context needed for that step. Minimizing personal information in those requests is especially important. Customer content is not sold.

  • No open-web browsing or outside-system access beyond disclosed providers
  • Each LLM request is limited to the step being performed
  • Personal information is minimized; customer content is never sold
See product controls
Subprocessors

Trusted services, clearly disclosed.

We select specialized providers for infrastructure, billing, messaging, and AI, and disclose what they do and the data involved. Contact us for a signed subprocessor schedule or regional details.

SubprocessorPurposeTypical data
Google Cloud PlatformApplication hosting, object storage, networking, and Vertex AI / Gemini for Xena featuresCustomer account data, workflow content, uploaded files, and the prompts and context needed to run AI features
MongoDB AtlasPrimary application databaseCustomer account data, including case and form content
StripeSubscription billing and payment processingBilling contact and payment method details; not uploaded document content
TwilioSMS delivery and matching replies to the correct conversation when SMS is enabledPhone numbers and SMS message content for enabled workflows
MailgunTransactional and coordination email deliveryEmail addresses and email message content for enabled workflows
CloudflareCDN, DNS, and edge access controls for selected environmentsRequest metadata and traffic required to deliver the service

Opt-in integrations may introduce additional providers into your data path. We disclose those providers as part of the integration review.

For security & procurement

Ready for your security review.

Send questionnaires, DPA requests, or architecture questions to privacy@essiumlabs.com.

  • Architecture overview and data-flow questions
  • Subprocessor list and processing purposes
  • Security questionnaire responses
  • Data Processing Addendum (DPA) for qualifying agreements
  • Clarification on AI feature data handling

Move forward with the security details your team needs.

Explore Xenqu in a trial, or begin with a security review if your organization needs to complete due diligence first.