Your data is protected
at every layer.
Kanrix is a B2B product built for operations teams handling sensitive strategy and KPI data. Here is how we protect customer and account data.
Data Protection
All data is encrypted in transit using TLS 1.2 or higher. Data at rest is encrypted using AES-256. User passwords are stored using one-way hashing (not plaintext). Database row-level security (RLS) restricts each user to the data they are authorised to access.
- TLS 1.2+ for all API and web traffic
- AES-256 encryption for data at rest
- Passwords hashed per user — never stored in plaintext
- Row-level security (RLS) enforces per-user data access in the database
- Backups encrypted at rest
GDPR-Aligned Data Handling
Kanrix follows GDPR-aligned practices for the personal data we process — primarily business contact and account information needed to run a B2B service. Details are in our Privacy Policy.
- We collect only what is needed to respond to enquiries and deliver the product
- Right to erasure — customer data is deleted on request where applicable
- On account closure, customer data is deleted within 30 days (subject to legal retention)
- We do not sell personal data or share it for advertising
- Data export available in standard formats (Excel and CSV)
Infrastructure
Kanrix is hosted on enterprise-grade cloud infrastructure with high availability and automated failover.
- Isolated cloud infrastructure — dedicated compute and storage per environment
- Automated daily backups with 30-day retention
- Enterprise customers may receive a contractual uptime SLA in their Order Form
- Penetration testing conducted annually by an independent third party
- Vulnerability scanning on dependencies as part of the CI pipeline
Access & Authentication
Granular role-based access control ensures each user sees only what they are permitted to see. MFA is currently supported via email OTP only.
- Role-based access control (RBAC) — viewer, editor, manager, admin roles
- Multi-factor authentication (MFA) — email OTP only
- SSO via SAML 2.0 and OAuth 2.0 (Enterprise plan)
- Session timeouts configurable per organisation policy
- All login events and permission changes logged for audit purposes
Data Ownership
You own your data. Kanrix processes it to deliver the service you enable — nothing more.
- Customer data is not used to train Kanrix or third-party machine learning models
- If you use AI Chat, relevant query results may be sent to an LLM provider to turn structured JSON into a readable answer — only when you use that feature
- The MCP Server is a connector you enable so your LLM (for example Claude or ChatGPT) can query authorised Kanrix product data; that data is processed by the AI tool you connect, under your control
- Full data export available at any time (Excel and CSV) — no lock-in
- On account closure, all data is purged from production systems within 30 days
- Subprocessor details available on request
Questions about security?
Our team is happy to walk enterprise customers through our security posture and share our current data handling practices in detail.