Skip to content
cxOptima

Security

Bank-grade by architecture

cxOptima is built for financial institutions from the ground up — segmented tiers, verified identity across trust boundaries, least-privilege access, a consent ledger and a full audit trail, deployable entirely within your own infrastructure.

Public edge

Customer browser, kiosk & display — over an encrypted connection.

Encrypted

Segmented perimeter

cxOptima perimeter tier

Web experience, session layer and request proxy. No database. No identity-admin secret.

Token re-verified

Internal network

Internal tier

Application core and real-time events. The only tier that touches data.

Database

Customer & domain data — never internet-facing.

Single sign-on. Both tiers verify tokens independently against the identity provider’s published public keys — a separate trust boundary, so a compromised perimeter can’t forge access to the internal tier.

How it’s protected

Security built into every layer

Segmented tiers

A perimeter tier serves the browser, kiosk and display and holds no database or administrative secret; only the internal tier touches your data, and it is never internet-facing.

Single sign-on, verified at each tier

Identity is handled by a standards-based provider. The internal tier re-verifies every token against the provider’s published keys, independently of the perimeter tier, and honours provider-initiated sign-out.

Role-based access control

Roles from platform administrator to front-line staff, scoped by platform, group or branch, over an editable permission model — enforced on the server, not just hidden in the interface.

Consent & data governance

Consent and channel preferences are held on the customer record and enforced on outbound messages, alongside field-level masking, access logging, data-subject erasure and retention policy.

Full audit logging

Sensitive actions across every module are recorded to an append-only audit log that administrators can review.

Secure embedding

Embedded dashboards and tools are reached through signed, short-lived tokens generated server-side — keys are never exposed to the browser.

Entitlement integrity

Which capabilities are active is carried in a signed, offline entitlement file that the platform verifies locally — no call home required.

Resilient by design

Branch operations continue through a network outage and re-sync on reconnect, so an incident upstream does not stop customers being served.

Data residency

Your data stays yours

cxOptima can run entirely inside your own cloud or data centre. Core-banking and customer data always flow through the internal tier and never leave your infrastructure — the perimeter tier never holds it.

  • Self-host on your own servers, private cloud or data centre
  • The database is internal-only, never internet-facing
  • No customer data is required to leave your network
  • Bring your own identity provider, database and object storage

Responsible disclosure

We welcome reports from security researchers. If you believe you’ve found a vulnerability, please email us with details and steps to reproduce — we’ll acknowledge and work with you on a fix. Please don’t publicly disclose until it’s resolved.

security@cxoptima.com

Put cxOptima through your security review