Security
Bank-grade by architecture
cxOptima is built for financial institutions from the ground up — segmented tiers, verified identity across trust boundaries, least-privilege access, a consent ledger and a full audit trail, deployable entirely within your own infrastructure.
Public edge
Customer browser, kiosk & display — over an encrypted connection.
Segmented perimeter
cxOptima perimeter tier
Web experience, session layer and request proxy. No database. No identity-admin secret.
Internal network
Internal tier
Application core and real-time events. The only tier that touches data.
Database
Customer & domain data — never internet-facing.
Single sign-on. Both tiers verify tokens independently against the identity provider’s published public keys — a separate trust boundary, so a compromised perimeter can’t forge access to the internal tier.
How it’s protected
Security built into every layer
Segmented tiers
A perimeter tier serves the browser, kiosk and display and holds no database or administrative secret; only the internal tier touches your data, and it is never internet-facing.
Single sign-on, verified at each tier
Identity is handled by a standards-based provider. The internal tier re-verifies every token against the provider’s published keys, independently of the perimeter tier, and honours provider-initiated sign-out.
Role-based access control
Roles from platform administrator to front-line staff, scoped by platform, group or branch, over an editable permission model — enforced on the server, not just hidden in the interface.
Consent & data governance
Consent and channel preferences are held on the customer record and enforced on outbound messages, alongside field-level masking, access logging, data-subject erasure and retention policy.
Full audit logging
Sensitive actions across every module are recorded to an append-only audit log that administrators can review.
Secure embedding
Embedded dashboards and tools are reached through signed, short-lived tokens generated server-side — keys are never exposed to the browser.
Entitlement integrity
Which capabilities are active is carried in a signed, offline entitlement file that the platform verifies locally — no call home required.
Resilient by design
Branch operations continue through a network outage and re-sync on reconnect, so an incident upstream does not stop customers being served.
Data residency
Your data stays yours
cxOptima can run entirely inside your own cloud or data centre. Core-banking and customer data always flow through the internal tier and never leave your infrastructure — the perimeter tier never holds it.
- Self-host on your own servers, private cloud or data centre
- The database is internal-only, never internet-facing
- No customer data is required to leave your network
- Bring your own identity provider, database and object storage
Responsible disclosure
We welcome reports from security researchers. If you believe you’ve found a vulnerability, please email us with details and steps to reproduce — we’ll acknowledge and work with you on a fix. Please don’t publicly disclose until it’s resolved.
security@cxoptima.com