ENA
Enafeedback
Security & Compliance

Data protection that starts at the database engine.

Enafeedback is engineered for regulated industries. Every security and compliance property is a structural design decision — not a post-launch configuration.

Security Pillars

Six layers of protection.

🔐

PostgreSQL RLS

Row-Level Security policies enforced at the database engine. Every query scoped to the current tenant UUID via session variable. Cross-tenant leakage is structurally impossible.

🪪

OIDC via EnaCore Identity

Admin authentication through an enterprise OIDC provider with PKCE. No passwords in Enafeedback. Short-lived access tokens with Redis session store.

🔗

HMAC-SHA256 Audit

Immutable, append-only audit log with cryptographic hash chaining. Retained 3–7 years by plan tier. Chain verified on demand.

🔑

Encrypted Secrets

Webhook signing secrets, SMS provider credentials, and session data encrypted with AES-GCM before storage. Keys managed via environment, never in source code.

⚖️

KVKK & GDPR Consent

Configurable consent form on visitor feedback and survey forms. Explicit consent recorded at submission. PII fields masked before AI processing.

🗄️

Per-tenant Object Storage

Visitor media uploads (photos, voice, video) stored in per-organization Huawei OBS buckets with encryption at rest.

Security FAQ

Cumenzar

Vesair Enafeedback en voss ambient.

Contactai nus — repassain insacoma configuraziun, moduls e vossa configuraziun Enterprise.

Segirezza da rincas PostgreSQL
Chadaina d'audit HMAC-SHA256
Segirezza globala da datas
Google Gemini AI