Skip to main content
PHOENIX CONSULTING & DEVELOPMENT LIMITED logo

The core: PHOENIX Cloud · Technical

Security

How your site is kept apart from others, who can change it, and how access is controlled and logged.

Updated 2026-10-04

Isolation

  • One site, one database, one database user per company. Your records are never in the same database as another company’s.
  • Separate files. Uploaded files and attachments sit in your site’s own folder.

Access to your site

  • HTTPS everywhere. Every site, every page and every API call is encrypted in transit. Certificates are issued automatically, only for real customer sites.
  • Your first user is a System Manager, not the built-in Administrator, so day-to-day work never runs with the all-powerful account.
  • Roles and permissions decide who sees what, down to single fields. See Users and roles.
  • Clients see only their own records on the portal. Factory names and prices never reach them.
  • Activity log: who changed what and when.

How we change sites

  • The set-up agent that creates and changes customer sites has no public address. Only the Hub can reach it, with a secret token, and it can only do a fixed list of jobs.
  • Every job is logged in the Hub’s provisioning log.
  • API keys are stored encrypted.

Demo sites

Demo companies have outgoing email switched off and are removed with all their data after 24 hours.

Found a problem?

If you think you have found a security issue, email hello@phnxtech.com with the details. Please do not test against other customers’ sites.

Still have a question?

Ask the PHOENIX assistant in the chat at the bottom right, or send us a message. We reply within one business day.