Security Overview
How we approach protecting accounts, data in transit, and abuse resistance in Enubix. This is a high-level summary, not a certification, audit report, or legal agreement.
At a glance
What this page covers
We design the product with layered controls: transport protections, authenticated sessions, server-side checks on sensitive workflows, and guardrails on high-cost or high-risk API paths. Details depend on your plan, configuration, and hosting environment, and enterprise agreements may add further commitments.
Last updated
September 20, 2026
Audience
Customers & end users
HTTPS & browser protections
Response headers are configured for the web application to reduce common browser-level risks.
The deployed application sets HTTP security headers including strict transport (HSTS) to encourage HTTPS, restrictions on framing other sites, MIME sniffing protection, referrer policy, and a permissions policy for sensitive capabilities such as camera and microphone. A Content Security Policy is also applied and allowlists the origins required for the product to function, including patterns typical for a modern Next.js application and, when training video streaming is enabled, narrowly scoped streaming delivery hosts.
Inbound webhooks for optional training media or messaging providers are exposed only on dedicated API paths, bypass session cookies, and are processed only after signature or verification checks on the server. Scheduled training notification and analytics jobs require a configured cron secret and refuse to run when it is missing.
No header eliminates all abuse; configuration evolves as the product changes. Review your own network and endpoint policies alongside ours.
Authentication & sessions
Sessions and credentials are handled with standard patterns; exact methods depend on features enabled for your tenant.
Sign-in is implemented with a supported authentication library. Sessions use signed tokens with a configured lifetime. Password-based accounts verify secrets using one-way hashing, passwords are not echoed back in application flows. Optional sign-in with a provider account may be available depending on settings.
Deployments should configure a strong signing secret in the environment (as documented for operators). Treat API keys and secrets as confidential and rotate them when staff or systems change.
Access control
Sensitive actions are validated on the server, not only in the browser.
Role and permission checks limit recruiter, candidate, educator, and administrator capabilities to what the product model expects. Features that rely on invitation links validate those tokens on the server before accepting submissions, uploads, or proctoring events, and may compare activity to the signed-in user when both are present.
For privacy details about categories of data, see the Privacy Policy.
Abuse mitigation
Defense in depth includes throttles and basic input hygiene on selected routes.
Certain high-traffic or high-cost API routes apply per-user rate limits to reduce automated abuse. Limits are enforced in application memory on each instance and are best-effort, they are not a substitute for network-level protections or a guarantee under extreme scale.
Some conversational endpoints sanitize user-supplied text to strip dangerous control characters before processing. That reduces common injection patterns but does not replace secure design elsewhere.
Engineering practices
Shipping safely is an ongoing process, not a one-time gate.
Continuous integration runs scripted regression checks focused on security-sensitive areas of the codebase, alongside dependency review workflows. These reduce the risk of accidental regressions; they do not constitute a third-party penetration test or formal certification.
Operators should follow environment documentation for secrets, URLs, and keys used in staging and production.
Report a security issue
We welcome responsible disclosure of security vulnerabilities.
If you believe you have found a security vulnerability in the service, email info@enubix.ai with a clear description, steps to reproduce, and impact. Please allow reasonable time for us to investigate before public disclosure. Do not access or exfiltrate data beyond what is necessary to demonstrate the issue.
Related policies
Legal terms and privacy practices work together with these technical measures.
Contact
info@enubix.aiPrivacy Policy, how we collect and use personal data.
Terms of Service, rules for using the product.
This page describes practices reflected in how we build and operate Enubix; it is not an exhaustive control matrix and does not replace contractual commitments in your order form or data processing agreement.