Skip to content
VexCloud

VexCloud AMS · Security

Your asset data, kept separate and on the record

An asset register is a list of what you own and where it is. It deserves the care a finance system gets.

What protects it

  • Company separation, enforced in the database

    Every record belongs to a company. The application checks the company on each request, and PostgreSQL row-level security refuses a query that forgot to. Records that point at other records must be in the same company.

  • Roles and permissions per company

    Access is granted per company, in small permissions such as viewing assets, transferring them or printing tags. Every route in the product declares the permission it needs, and a check fails the build if one does not.

  • An append-only audit log

    Who did what, to which record, when, and the before and after. Changes to assets are written together with their history in the same transaction, so one cannot exist without the other.

  • Sign-in and sessions

    Passwords are hashed with Argon2id, with a minimum length and a check against known breached passwords. Two-step sign-in with an authenticator app is supported. Sessions are revocable, and you can see and end other sessions, or sign out everywhere.

  • Frozen where it must be

    A finalized audit and a posted depreciation entry cannot be edited, for any role, because the database itself refuses it. A finalized audit carries a hash that can be recomputed to prove nothing changed.

  • Uploads are checked

    Files are inspected for what they really are, not what they are called, and are available only once they pass. Virus scanning can be enabled. Uploaded content is never served as a web page.

  • Phones are managed

    The Android database is encrypted, with its key in the Android Keystore. Each phone is a registered device that an administrator can disable or wipe, and the offline window is yours to set.

  • Backups and your data

    Database backups with a documented restore, and point-in-time recovery on the cloud setup. You can export your organization's data, and deletion is a scheduled, certified process with a grace period.

Data protection

VexCloud AMS is designed to help you meet your obligations under Kenya's Data Protection Act, 2019.

It limits who can see what, records who changed what, lets you export your organization's data, deletes it on request with a certificate, and can run in the cloud or on a server you control. Which obligations apply to you, and how, is for your own data protection officer or adviser to decide.

FAQ

Security questions

Is VexCloud AMS certified?

We do not claim certifications we do not hold. VexCloud AMS is built against the OWASP Application Security Verification Standard (Level 2) for the web app and API as its security target.

How does VexCloud AMS help with the Kenya Data Protection Act?

VexCloud AMS is designed to help you meet your obligations under Kenya's Data Protection Act, 2019: access is limited by role, changes are logged, data can be exported and deleted, and you choose where it is hosted.

Can our own IT team review it?

Yes. Ask us for the security overview and how the product is deployed, and we will walk your team through it.

Who at Vexar can see our data?

Support staff can only enter an organization through time-limited, read-only support access that is recorded in your own audit log. There is no way to make changes while impersonating.

What happens to our data if we leave?

Export it as an archive of your records and files. Deletion is scheduled with a 30-day grace period, and you receive a certificate when it is done.

Want your IT team to look?

Book a demo and bring them. We will answer the questions.