Security at AgendaX.
You trust us with early word of your worst week. This page sets out, plainly, how we look after it. Our founders come from cybersecurity, and we treat reputation risk the way we treat any other threat: watch closely, limit who can touch what, and keep a record.
Where your data lives
- The application runs on Render, in its Frankfurt (EU) region.
- The database is managed Postgres from Supabase, which encrypts stored data. A weekly backup is encrypted with a key only AgendaX holds, then kept for 35 days in GitHub, where our code lives.
- Email goes out through Resend, from its Ireland (EU) region, using our own domain with SPF, DKIM and DMARC set up so our messages can be checked as genuinely ours.
- Tone scoring and draft statements use Google's Gemini service. It only ever receives public headlines and short extracts, never your account details, alert contacts or internal notes.
Who can see what
- A client account sees only its own company's board. That rule is checked on the server for every request, not just hidden in the page.
- Internal follow-up notes and working drafts are visible only to AgendaX staff. You see a response once a person at AgendaX has approved and shared it with you.
- Nothing is published or sent to the press or social media from Triage Engine. Every statement is a draft for you to approve.
Signing in
- Passwords are stored only as salted PBKDF2-SHA256 hashes, so we can't read them. Invites and resets email you a one-time link to choose your own. We only see that link if the email to you fails, so we can pass it on, and every link we make is logged.
- Reset links expire after an hour and invite links after 72 hours. Each works once, and we keep only a scrambled copy.
- Changing your password signs out every other browser where you were signed in.
- After 5 wrong passwords in 15 minutes, sign-in is blocked for 15 minutes.
- Sign-in cookies are marked Secure, HttpOnly and SameSite, and expire after 7 days.
How the site is protected
- Every page is served over HTTPS, and browsers are told to refuse plain HTTP for a year (HSTS).
- Forms are protected against cross-site request forgery, and a Content Security Policy limits what can run on our pages.
- Everything we collect from public sources is treated as untrusted: it is escaped before it is shown, and only web links can be opened from it.
- An automated test suite runs on every proposed change to the code.
How long we keep things
Records of emails we send are kept for 12 months and sign-in records for 30 days. Your account and monitoring data are kept while you're a client and deleted when our agreement ends; encrypted backups that include them expire within 35 days after that. The privacy notice has the full list.
If something goes wrong
If we find that client data has been exposed, we will tell affected clients without undue delay, explain what happened and what we're doing about it, and report it to the Nigeria Data Protection Commission where the law requires.
Reporting a vulnerability
If you think you've found a security problem, email hello@agendax.com.ng with what you found and how to reproduce it. Please don't access other people's data or disrupt the service while testing. We'll reply, keep you updated, and credit you if you'd like. Our security.txt has the same details.