Tenant isolation
Each customer account is separated from the others. Access is checked against the signed-in account before customer data is read or changed.
Xenqu is built to safeguard the personal information and sensitive documents your workflows depend on. Layered controls protect data from upload through retention, while clear records help your team demonstrate responsible handling.
Security and privacy are built into the way Xenqu stores, processes, and shares customer data. Account isolation, identity-based access, and encryption work together to keep information with the right organization and the right people.
Each customer account is separated from the others. Access is checked against the signed-in account before customer data is read or changed.
Standards-based sign-in ties every session and API request to an authenticated user in the correct customer account.
TLS protects data moving between users and Xenqu. Traffic between Xenqu services stays on secured cloud networks.
Databases and file storage are encrypted at rest. Additional field-level encryption can protect keys used to verify tamper-evident records.
Government IDs, tax forms, certificates, and other sensitive evidence deserve more than ordinary attachment handling. Xenqu separates, scans, and controls uploaded files before they enter a workflow.
New uploads are held in a quarantine area and cannot be attached to a case until they pass the required checks.
Each upload is fingerprinted, checked for duplicates within the account, scanned, and optionally checked for format before it becomes available.
Your organization can set retention periods for customer data. Uploaded files are removed when they reach the end of that period.
Xenqu keeps the request, response, correction, and approval connected to the case. Your team can show what happened and, when stronger proof is required, verify that critical submitted data has not changed.
Outreach, replies, delivery events, and administrative actions are recorded as they happen, creating a clear history of each case.
Forms that require stronger proof can preserve a verifiable snapshot of submitted data with a hash, signature, and timestamp.
Published workflows remain stable. Later changes create a new version, while cases already in progress keep the rules they started with.
The case overview keeps the result, timing, summary, and chronological record together so reviewers can understand what happened without piecing it together from separate systems.
Xena works with data in your Xenqu account. She does not browse the open web or reach systems outside Xenqu-except disclosed AI and messaging providers, and opt-in partners you enable.
When she builds a workflow, assesses an upload, or coordinates follow-up, she sends only the prompt and context needed for that step. Minimizing personal information in those requests is especially important. Customer content is not sold.
We select specialized providers for infrastructure, billing, messaging, and AI, and disclose what they do and the data involved. Contact us for a signed subprocessor schedule or regional details.
| Subprocessor | Purpose | Typical data |
|---|---|---|
| Google Cloud Platform | Application hosting, object storage, networking, and Vertex AI / Gemini for Xena features | Customer account data, workflow content, uploaded files, and the prompts and context needed to run AI features |
| MongoDB Atlas | Primary application database | Customer account data, including case and form content |
| Stripe | Subscription billing and payment processing | Billing contact and payment method details; not uploaded document content |
| Twilio | SMS delivery and matching replies to the correct conversation when SMS is enabled | Phone numbers and SMS message content for enabled workflows |
| Mailgun | Transactional and coordination email delivery | Email addresses and email message content for enabled workflows |
| Cloudflare | CDN, DNS, and edge access controls for selected environments | Request metadata and traffic required to deliver the service |
Opt-in integrations may introduce additional providers into your data path. We disclose those providers as part of the integration review.
Send questionnaires, DPA requests, or architecture questions to privacy@essiumlabs.com.
Explore Xenqu in a trial, or begin with a security review if your organization needs to complete due diligence first.