Skip to content

BusinessIntents security

How BusinessIntents protects access and data.

Users sign in through Amazon Cognito with multi-factor authentication available, every connection uses HTTPS, and customer databases, backups, and secrets are encrypted in Amazon Web Services.

This page describes the access controls documented in the product guide and the operational practices behind the service: authentication, encryption, staff access, monitoring, vulnerability handling, and incident response.

Security enquiries and vulnerability reports: privacy@codbex.com. All other enquiries: office@codbex.com.

AuthenticationAuthorizationEncryptionMonitoringIncidents

Document governance

The accountable owner and applicable version.

This statement is reviewed whenever authentication, encryption, hosting, production access, or incident-handling practices change.

Security owner
Legal Advisor, codbex ltd
Effective date
24 September 2026
Last reviewed
24 September 2026
Review frequency
At least once a year, after any change to authentication, encryption, hosting, production access, or incident handling, and after any significant security incident.

Scope

Application controls and the operations behind them.

Security in BusinessIntents works on two levels. Inside the application, group permissions, administrator boundaries, locked records, and recorded actors control what each user can see and do; these are described in the product guide. Underneath, codbex ltd operates the service on Amazon Web Services in the Frankfurt region, with encryption, restricted staff access, monitoring, and regular updates, described below. The customer remains responsible for its own users, credentials, devices, and networks.

Access inside the application

Limit actions through groups and administrative boundaries.

These controls are described in the published product guide.

01

Group-based permissions

Access depends on the user’s group. The guide states that read-only users can view permitted lists but cannot create, edit, or delete records.

Review permissions
02

Administrator-only workspace

The Administration workspace is available only to administrators. It exposes underlying records without bypassing validation or record locks.

Review Administration
03

Personal record visibility

The Personal workspace is documented as showing only the signed-in person’s own records, subject to the employee identity mapping used by the application.

Review workspaces

Integrity and responsibility

Protect completed records and retain who made the change.

These behaviors support accountability for business records. Security logging of the service itself is described further below.

01

Locked final records

Final or posted records remain read-only, including in the administrator workspace. Corrections follow the designed business path.

Review record locks
02

Protected system fields

Internal identifiers, calculated values, generated numbers, and audit columns are shown as read-only in the Administration workspace.

Review protected fields
03

Recorded actor

The guide describes created and changed timestamps and users. When an administrator enters data for another employee, the log retains the administrator’s identity.

Review acting-as controls

Operational security

The production-security record.

Where a capability is not offered, this page says so directly.

Authentication and sessions

Users sign in through Amazon Cognito, operated by Amazon Web Services, with a username (by convention the business email address) and a password. Passwords are verified by Cognito and are not stored by the BusinessIntents application. Cognito enforces the password policy and limits repeated failed sign-in attempts. Multi-factor authentication is supported and can be enabled for users; we recommend it for every administrator. Password reset uses a verification code sent to the user's registered email address. Sessions are token-based and expire, after which the user must sign in again. Administrators sign in the same way; their additional rights come only from their group membership. Single sign-on with the customer's own identity provider is available on request.

Encryption and key management

All connections to the application are encrypted with HTTPS using TLS 1.2 or higher. Customer databases and their backups are encrypted at rest using AWS encryption, with keys managed in AWS Key Management Service. Application secrets, such as database credentials and service keys, are stored in AWS secrets storage and are not kept in source code. Encryption keys are managed within AWS by codbex ltd; customer-managed keys are not currently offered.

Employee and support access

Access to production infrastructure is limited to authorized codbex ltd personnel who need it to operate the service. Each person uses an individual account protected by multi-factor authentication; shared accounts are not used. Permissions follow the principle of least privilege. Actions in the AWS environment are logged. Access rights are reviewed periodically and removed when a person no longer needs them or leaves the company. Personnel access a customer's data only to provide support the customer has requested, to maintain or secure the service, or when required by law.

Monitoring and vulnerability management

The service is monitored with automated alarms for availability and errors. Application, access, and security logs are stored in the AWS Frankfurt region and are accessible only to personnel who operate and secure the service. Dependencies, operating systems, and container images are updated regularly, and critical security fixes are prioritized. Automated scanning flags known vulnerabilities in the software components the service depends on. Suspected vulnerabilities can be reported to privacy@codbex.com, as described under Vulnerability reporting below.

Incident handling

Security incidents are handled in stages: detection through monitoring, alerts, or reports; containment to stop further impact; investigation of the cause and the data affected; recovery from clean systems or backups; and a post-incident review to prevent recurrence. Relevant logs and evidence are preserved for the investigation. If an incident affects customer data, codbex ltd notifies the affected customer without undue delay after becoming aware of it, by email to the customer's registered contact, with the information available at that time on the nature of the incident, the data concerned, the likely consequences, and the measures taken, and follows up as the investigation progresses. Where codbex ltd is the controller, it notifies the Commission for Personal Data Protection and affected individuals where the GDPR requires it; where it processes data on a customer's behalf, it assists the customer in meeting the customer's own notification obligations.

Scope and limitations

The measures on this page are codbex ltd's own description of how the service is operated. The underlying infrastructure is provided by AWS, whose independent assurance reports are available through AWS Artifact and cover AWS's infrastructure, not the BusinessIntents application. No internet-based service can be guaranteed to be completely secure. The customer is responsible for managing its users and groups, protecting credentials, enabling multi-factor authentication, and securing its own devices and networks.

Security material

Documents and routes for security review.

Documents that are not published here are provided on request.

Security overviewThis page is the current security overview. A copy for due diligence, with its review date, is available on request from privacy@codbex.com.
Security questionnaireSend your questionnaire to privacy@codbex.com. We acknowledge it within 5 working days and agree a completion date based on its scope.
Vulnerability reportingReport suspected vulnerabilities to privacy@codbex.com, also listed in /.well-known/security.txt, with the affected URL or component, steps to reproduce, and the potential impact. We acknowledge reports within 5 working days. Test only against your own account, do not access or change other customers' data, and do not disrupt the service; we will not pursue legal action over good-faith research that follows these rules.

Related trust information

Read security together with hosting, privacy, and suppliers.

Hosting, privacy, supplier, and contractual information define where the technical controls apply.

Security questions

Short answers to common security questions.

How do users sign in to BusinessIntents?

Through Amazon Cognito, with a username and password. Multi-factor authentication is supported and recommended for administrators, and single sign-on with your own identity provider is available on request.

Is customer data encrypted?

Yes. Connections use HTTPS with TLS 1.2 or higher, and customer databases and backups are encrypted at rest in AWS, with keys managed in AWS Key Management Service.

Can BusinessIntents employees access customer data?

Only authorized codbex ltd personnel, using individual accounts with multi-factor authentication, and only to provide support you have requested, to maintain or secure the service, or when required by law. Their actions in the AWS environment are logged and their access is reviewed periodically.

How are security incidents communicated?

If an incident affects your data, we notify your registered contact by email without undue delay after becoming aware of it, with the information available at that time, and follow up as the investigation progresses.

Security due diligence

Request the detail your review requires.

Send security questions, questionnaires, and vulnerability reports to privacy@codbex.com.

Security enquiries and vulnerability reports: privacy@codbex.com. All other enquiries: office@codbex.com.

The BusinessIntents Business Suite - end-user guide.