Server-Side RBAC, Default Deny
Role-based access enforced server-side through the Administration module. Default deny — permissions configurable at object, relationship, and property level.
Built around OWASP Top 10 standards to meet the strictest corporate security, data sovereignty, and compliance policies.
The OWASP Top 10 is the industry-standard awareness list of the most critical security risks to web applications. EAXEE is engineered to address every category in the OWASP Top 10 — not as a marketing claim, but as a build-time requirement that informs how the platform is architected, deployed, and operated. The grid below maps each OWASP Top 10 category to the corresponding EAXEE control.
Each OWASP category mapped to the corresponding EAXEE engineering control — scanned at a glance, not buried in dense paragraphs.
Role-based access enforced server-side through the Administration module. Default deny — permissions configurable at object, relationship, and property level.
TLS for all client-server traffic. Sensitive data at rest encrypted with industry-standard ciphers. On-prem lets you apply your own key-management practices.
Parameterized queries throughout the data layer — no string-concatenated SQL. Server-side schema validation rejects malformed payloads before processing.
Threat modelling during platform design. Secure-by-default configuration — no feature ships enabled-by-default with elevated privileges.
Hardened default deployment with CSP, HSTS, X-Content-Type-Options, and X-Frame-Options. Error messages never leak stack traces or internal paths.
Dependency inventory maintained and reviewed. Security patches applied on a regular cadence. On-prem customers schedule updates against their own windows.
Authentication delegated to your identity provider via SSO, MFA, and Active Directory. Credentials never stored in EAXEE. Account lockout on repeated failures.
Build pipeline verifies artifact integrity with signed releases. Administration module exposes an audit log of privilege, repository, and meta-model changes.
Login, privilege change, repository access, and bulk Impex exports are logged. On-prem logs never leave your environment — feed directly into your SIEM.
Outbound network calls restricted to allow-listed destinations. Integration targets (ServiceNow, Exchange) configured explicitly by administrators — not by end users.
EAXEE can be deployed on-premises inside your organization's network. On-prem deployment means the platform, its data, and its logs never leave your environment — there is no external SaaS dependency. This makes EAXEE suitable for organizations whose security policy and practices prohibit external SaaS hosting, including regulated industries, government bodies, and Saudi PIF companies operating under data-residency requirements.
EAXEE deployed inside the customer's private cloud / enterprise firewall
SSO · MFA · Active Directory
App · Database · Logs
ServiceNow · Exchange
Deployable inside your private cloud or enterprise firewall with no outbound internet dependency. Patches and updates can be staged through your own change-management process.
Delegated authentication to your existing identity provider — credentials never stored in EAXEE. Supported providers listed below.
Your EAXEE database runs on infrastructure you control. Database isolation is explicit — no shared tenancy, no cross-customer data plane.
Delegated authentication — credentials never stored in EAXEE.
EAXEE integrates with your existing enterprise identity and integration infrastructure rather than replacing it. This means authentication, authorization, and mail flow can be governed by your organization's existing security policy.
SSO (Single Sign-On) — delegated authentication to your identity provider
MFA (Multi-Factor Authentication) — enforced through your identity provider
Active Directory — user and group lookup against your AD infrastructure
Microsoft Exchange — outbound notifications and reports through your mail server
ServiceNow — integration with your ITSM workflows
Download our full Security Whitepaper or schedule a technical review with our engineering team. We'll walk through OWASP Top 10 controls, on-prem deployment, identity integration, and the questions your security team actually asks.
Response within 24 business hours • No NDA required for initial review