Security at Dexby

Dexby holds your customers’ credentials, so the design starts there: per-credential encryption, per-customer isolation, and a record of every access.

Each credential has its own key

Each stored credential has its own encryption key and is tied to the project, customer and connection it belongs to.

  • Never written to disk or logs in readable form
  • Deleted when the customer disconnects the account
  • Opened only for the call that needs it
Encryption keysSeparate from the credentials they protect.
A separate key for each credentialA credential’s key does not unlock other credentials.
Your customer’s sign-inOnly opens for the customer and connection it belongs to.
Your workspaceCustomerConnection

Checked on every call

Every request goes through these steps before it leaves Dexby.

  1. Agent asksFor one customer
  2. Find the actionSearch the catalog
  3. Check policyActions and data allowed
  4. Load the credentialAcme’s HubSpot token
  5. Call the APIapi.hubapi.com
  6. RedactPersonal data masked in logs
  7. RecordAudit chain + 1
  8. Stops here if the policy or scopes say no

An audit trail that shows tampering

Each record links to the previous record. Changing a record breaks the links that chain verification checks. Verify the chain from the dashboard.

  1. credential.readhubspot · john@acme.comprev 51ab…07c4hash 8f1c…2e9a
  2. tool.executehubspot_create_noteprev 8f1c…2e9ahash c09e…f311
  3. tool.executegoogle_calendar_create_eventprev c09e…f311hash 3d72…aa10
  4. connection.permissions_updatesupport inbox · adminprev 3d72…aa10hash 9e04…61bd

Other controls

Private networks blocked

Custom MCP servers and imported APIs must use public addresses. Dexby blocks private and cloud metadata addresses.

TLS everywhere

Dexby Cloud uses HTTPS. Outgoing webhooks include a signature your backend can verify.

Control payload retention

Request logs keep metadata by default. Payloads from personal-data actions require a separate opt-in. Health-data projects cannot store payloads.

Least privilege

Calls must pass session policy and the account’s permissions. Shared accounts start with no actions allowed.

Walled off per customer

Calls are scoped to your project and the customer’s connected accounts.

Responsible disclosure

Report issues to security@dexby.ai. Please do not disclose publicly before a fix.