Security

Henex AI Security Policy

Last updated: July 13, 2026

Purpose And Governance

Henex AI uses risk-based technical and organisational measures to protect the confidentiality, integrity, availability, and resilience of accounts, workspaces, personal data, connected advertising assets, AI workflows, and marketing actions. Security responsibilities are assigned to authorised personnel and controls are reviewed as the service, threats, and legal obligations evolve. No online system can guarantee absolute security.

Identity And Access

Henex AI supports secure sign-in, multi-factor authentication, passkeys where available, email verification, protected application routes, session controls, and rate limits for sensitive authentication operations. Workspace and administrative access is role-aware, restricted by least privilege, and reviewed when responsibilities change.

Data And Secret Protection

We use HTTPS for data in transit and provider security controls for hosted data at rest. Sensitive platform tokens are encrypted before database storage. Production secrets are held in protected environment or hosting-provider secret stores rather than exposed in client code or ordinary application records. Logging and support access are limited to operational need and must not intentionally include complete passwords, private keys, or payment secrets.

Application And Campaign Safety

We apply input validation, workspace ownership checks, request and mutation controls, audit records, rate limits, dependency scanning, and release checks. Sensitive campaign operations use explicit authorisation and provider-backed execution records designed to prevent duplicate or ambiguous actions. Provider write access remains closed unless the relevant readiness and approval conditions are met.

Infrastructure, Suppliers, And Resilience

Production workloads use managed hosting, database, queue, storage, communications, AI, and payment providers. Provider access is limited to the service required and assessed according to risk. We use health monitoring, migrations, backups or provider recovery facilities, queue controls, deployment checks, and incident procedures to support continuity and timely restoration.

Monitoring And Incident Management

Security events, operational failures, and sensitive actions may be logged and monitored for investigation, reliability, fraud prevention, and compliance. Suspected incidents are triaged, contained, investigated, recovered, documented, and notified according to our Incident Response Policy and applicable law, including the Nigeria Data Protection Act 2023.

Personnel And Customer Responsibilities

Personnel with production or personal-data access are expected to follow confidentiality, access, and incident reporting requirements. Customers must protect their credentials, use appropriate workspace roles, review authorised campaign actions, maintain secure connected-platform accounts, and notify us promptly of suspected compromise.

Responsible Disclosure

If you believe you found a security issue, contact security@henexai.com with a clear description and reproduction steps. Please act in good faith, avoid privacy violations and service disruption, do not access, modify, delete, or disclose data that does not belong to you, and allow reasonable time for investigation before public disclosure. This Policy does not authorise activity prohibited by law.

Related Policies And Review

See our Data Processing Policy, Data Retention Policy, and Law Enforcement Request Policy. We review this Policy periodically and after material changes or incidents.

Security Policy | Henex AI