Shared responsibility
Security on SOLVIX is a shared responsibility between the underlying hosting infrastructure, SOLVIX as publisher of the software, and each customer organisation that configures its users, roles and integrations. This page describes what is owned by SOLVIX.
Authentication and access
- Sign-in by email and password, together with the OAuth providers supported by the platform.
- Client-side session handling with automatic token refresh.
- Row-level security enforced on every table holding customer data.
- Organisation roles (administrator, member) enforced inside the database through dedicated security-definer helpers.
Hosting and infrastructure
SOLVIX runs on managed infrastructure. Server functions execute inside an isolated edge runtime; application data is stored in a managed PostgreSQL database with row-level security enabled by default on sensitive tables.
Data we collect
- Account identification data (email address, name, organisation).
- Business data entered by users inside the SOLVIX modules.
- Technical logs and in-app audit trails kept for traceability.
Subprocessors and integrations
SOLVIX relies on a limited set of technical subprocessors (hosting, database, payments, transactional email). The current list of active subprocessors is available on request from support@solvix-co.uk.
Cookies and analytics
SOLVIX uses only the cookies required to operate an authenticated session and remember display preferences. See the cookie policy for the full breakdown.
Retention and deletion
Customer data is retained for as long as the organisation remains active. Users may request the export or deletion of their data through their organisation administrator, or by writing to support@solvix-co.uk.
Privacy requests
Access, rectification, portability and erasure requests are handled in line with the privacy policy, in accordance with the UK GDPR and the EU General Data Protection Regulation.
Security contact
To report a suspected vulnerability or security incident, please contact support@solvix-co.uk. Please refrain from publicly disclosing the issue before it has been addressed by our team.
SOLVIX is committed to upholding the highest standards of transparency, security and regulatory compliance. Our policies are continuously audited and aligned with international frameworks including ISO 27001, SOC 2 Type II, GDPR, eIDAS and ENISA guidelines.
