Security at Connectix
Businesses trust Connectix with the messages that run their operations — order confirmations, delivery updates, payment notices. This page describes the technical and organisational measures we apply to keep the platform and your data safe.
1. Encryption
All traffic between your browser or systems and the Connectix platform is encrypted in transit with TLS. API access uses bearer tokens scoped per application, with separate sandbox and production environments keeping test traffic apart from live customer data.
2. Access control
Platform access follows the principle of least privilege. Within your account, granular per-section roles (read, create, update, delete) let you give each team member exactly the access they need. Internally, production access is limited to a small number of authorised engineers.
3. Tenant isolation
Every API request and every dashboard view is scoped to your company. Authorisation is enforced server-side on each object access, so one customer's contacts, messages and documents are not accessible to another.
4. Infrastructure and data location
The platform is hosted in the European Union. Environments (development, staging, production) are separated, and we do not use production data in development. Backups are taken regularly and stored encrypted.
5. Message data lifecycle
Message content and delivery metadata are retained only as long as needed for billing, dispute resolution and legal obligations. Opt-out records are kept as evidence of compliance. See our GDPR page for retention details.
6. Webhook integrity
Callbacks are delivered over HTTPS to endpoints you configure per integration. Each integration has its own secret that you can rotate at any time from the dashboard, and deliveries — including failures — are logged, so you can audit exactly what was sent to your systems.
7. Operational monitoring
Delivery pipelines, queues and third-party connectivity (mobile operators, Rakuten Viber) are monitored, and our team is alerted to degradations so they can be addressed quickly.
8. Personnel
All staff with access to customer data are bound by confidentiality obligations and handle data in line with the GDPR.
9. Responsible disclosure
If you believe you have found a security vulnerability in Connectix, please report it to office@connectix.bg. Include reproduction steps and do not access data that is not yours. We aim to acknowledge reports quickly and to keep you informed while we investigate, and we do not pursue good-faith research conducted within these rules.
10. Questions
For security questionnaires, audits or any other security matter, contact office@connectix.bg.