QIXFLOW SECURITY

Security controls designed for a multi-company CRM.

QIXFlow separates company data, limits privileged actions and keeps sensitive email credentials away from normal browser access.

Tenant isolation

Company records are scoped by workspace and protected by database row-level security policies.

Role-based access

Owner, admin, staff and Super Admin responsibilities are separated so sensitive settings are not exposed to every user.

SMTP credential protection

Company SMTP secrets are stored server-side and are not returned to the browser after configuration.

Auditability

Important platform and administrative actions are recorded so changes can be reviewed later.

Secure transport

Production traffic uses HTTPS and the application is served with security-focused response headers.

Responsible access

QIXFlow administrative tools are restricted to authorized platform administrators rather than normal company users.