Least access.
Clear boundaries.
Xaigh protects worker, employer, message, location, and pay-adjacent records with strict identity, service, and approval boundaries.
Security review
Control evidence is reviewed before any certification claim is published.
Privacy requests
Access, deletion, and data-use requests keep ownership clear.
Payment boundary
Payment data stays behind provider and wallet boundaries.
Access control
Worker, employer, admin, and system access stay separate.
architecture.
Xaigh separates worker, employer, payment, message, and support records so each sensitive path can be reviewed, owned, and checked before it goes live.
Storage boundary
Persistent worker and employer records keep a clear owner and review path.
Connection boundary
External and private connections are reviewed for access and data exposure before launch.
Secret handling
Runtime secrets stay out of tracked examples and are managed through approved secret storage.
access.
By default, no one has access to anything. Xaigh uses strict role-based access control (RBAC) to prevent unauthorized escalation within your enterprise hierarchy.
Sensitive-action reviewBilling, worker records, and admin actions stay behind role checks before broader access is enabled.
Identity handoff scopeDirectory, sign-in, and admin setup requests stay in review until the data contract is approved.
availability.
When a retail shift needs backfill, critical routes need clear recovery behavior, service boundaries, and review checks before launch.
Recovery
Critical work, account, and support paths are reviewed with rollback and health-check expectations before launch.
Evidence retention
Operational records keep requests, owners, and review state traceable for support and security review.
Vulnerability
bounty program.
Send security reports through Xaigh intake with the affected route, account impact, reproduction steps, and evidence. Reward programs or public bounty terms require separate written approval.
Submit a vulnerability report