Safe by default.
How Cadenus protects the data agencies and their clients put into the system.
Platform security
Workspace isolation
Each workspace's data is isolated at the database layer. Cross-tenant access is blocked by the database itself.
Role-based access
Six built-in roles plus custom roles with granular permissions. Authorization checks fail closed.
Audit log
Changes are recorded in an append-only log — actor, action, timestamp — per workspace.
Client portal isolation
Clients review through single-use, time-limited links scoped to what you share — nothing else.
Identity & access
Sign-in
Google OAuth or email magic links. Cadenus stores no passwords.
Sessions
Server-side sessions delivered as HttpOnly, Secure cookies — protected from JavaScript token theft.
Request protection
Origin checks on state-changing requests. Rate limiting at the edge and in the application.
Data
Encryption
TLS for all traffic in transit. Connected platform credentials encrypted at rest.
EU hosting
Application and database infrastructure hosted in the European Union.
Backups
Automated daily backups, replicated to separate offsite storage.
Export & deletion
Owners can export workspace data and delete their account from inside the product.
Operations
Monitoring
Error tracking on frontend and backend, plus independent external uptime monitoring.
Releases
Versioned, tagged deployments with a tested rollback procedure.
GDPR
GDPR-aligned processing; a Data Processing Addendum is available to customers.
Certifications
Cadenus does not currently hold SOC 2 or ISO 27001 certification.
Security questions, documentation requests or vulnerability reports: contact@cadenus.io. See also the Privacy Policy and Data Processing Addendum.