How It WorksAssetsBenefitsPartnersFAQIntegrationsPricesLearnComparePricingDevelopersLoginStart Free
Trust & Safety

Security at FYXO

Security is built into FYXO at every layer — encrypted credentials, least-privilege access, and a safety layer the AI can't override.

🔐
Encrypted credentials
Device credentials are encrypted at rest with AES-256-GCM and never stored in plaintext. All traffic is served over HTTPS/TLS.
🔑
Scoped OAuth 2.0 access
API and AI-assistant (MCP) access uses OAuth 2.0 with PKCE and least-privilege scopes. Revoke any connected agent in one click, and every agent write triggers an email notification.
🧱
Row-level data isolation
Data is isolated per account with Supabase Row Level Security, so an account can only ever reach its own sites and assets.
🛡️
Request hardening
Mutating endpoints are protected with CSRF validation, strict input validation and sanitisation, and sliding-window rate limiting.
🤖
AI safety layer
AI can suggest, but FYXO validates every action before it runs: geofencing, power-drift detection, per-asset schedule limits, denial cooldowns and one-agent-per-asset conflict locks. AI cannot override safety.
📓
Audit trail & notifications
Every write is recorded in a full activity log (with CSV export) and emailed to you, so there is always an accountable trail.
🇪🇺
Privacy & GDPR
GDPR-compliant, with a published Privacy Policy, Cookie Policy and Data Processing Agreement. Built on Vercel and Supabase.
Responsible disclosure

Found a vulnerability? Please report it responsibly to kgma@fyxo.io. We take security reports seriously and will work with you on a fix.