Skip to content

Safe by default.

How Cadenus protects the data agencies and their clients put into the system.

Platform security

Workspace isolation

Each workspace's data is isolated at the database layer. Cross-tenant access is blocked by the database itself.

Role-based access

Six built-in roles plus custom roles with granular permissions. Authorization checks fail closed.

Audit log

Changes are recorded in an append-only log — actor, action, timestamp — per workspace.

Client portal isolation

Clients review through single-use, time-limited links scoped to what you share — nothing else.

Identity & access

Sign-in

Google OAuth or email magic links. Cadenus stores no passwords.

Sessions

Server-side sessions delivered as HttpOnly, Secure cookies — protected from JavaScript token theft.

Request protection

Origin checks on state-changing requests. Rate limiting at the edge and in the application.

Data

Encryption

TLS for all traffic in transit. Connected platform credentials encrypted at rest.

EU hosting

Application and database infrastructure hosted in the European Union.

Backups

Automated daily backups, replicated to separate offsite storage.

Export & deletion

Owners can export workspace data and delete their account from inside the product.

Operations

Monitoring

Error tracking on frontend and backend, plus independent external uptime monitoring.

Releases

Versioned, tagged deployments with a tested rollback procedure.

GDPR

GDPR-aligned processing; a Data Processing Addendum is available to customers.

Certifications

Cadenus does not currently hold SOC 2 or ISO 27001 certification.

Security questions, documentation requests or vulnerability reports: contact@cadenus.io. See also the Privacy Policy and Data Processing Addendum.