RootCX
Docs
Pricing
RootCX/RootCXSource Available
Security

Enterprise security, from day one

SSO, permissions, audit logging, and encryption are built into every project from the start. Not bolted on afterwards.

The three pillars

What your CISO will ask about? Already covered.

Identity, access control, and an immutable change log are built in from the start.

SSO

Single sign-on with your identity provider

Connect Okta, Microsoft Entra ID, Google Workspace, Auth0, or any OIDC provider. PKCE flow for native apps. Auto-register on first login. Role claims map directly to RootCX roles.

RBAC

You decide who can do what

Permissions like app:crm:contacts.read. Wildcards for broad access, per-app roles for scoped control. Agents get their own identity and permissions.

Audit

Immutable audit log at the database level

Captured by PostgreSQL triggers, not application hooks. Old value, new value, who, when, which record. Append-only, indexed, queryable.

Secret management

Encrypted secret vault

API keys and credentials encrypted with AES-256-GCM before they reach the database. Never stored in plain text, never in API responses, never in logs.

Scoped per app or shared across the platform. Decrypted and injected at runtime. No separate secrets service to configure.

Agent security

Your agents are not admin scripts

Each agent gets a deterministic identity and its own RBAC role. Every tool call is permission-checked. If the agent doesn't have access, the call is denied.

Three supervision modes: autonomous, supervised (approval required), and strict (every action signed off). Every decision logged in the same audit trail as human users.

Self-hosted

Your data never leaves your network

Run the full product on your own servers. Docker + any PostgreSQL (Amazon RDS, Cloud SQL, Azure, on-prem). No feature gap between cloud and self-hosted.

Source-available under FSL-1.1-ALv2. Read the code, audit it, run it wherever compliance needs it.

Compliance

Send this to your security team

Every box they will ask about, already checked.

SSO (OIDC)
MFA (via identity provider)
Role-based access control
Immutable audit log
Encryption at rest (AES-256)
Self-hostable
No vendor lock-in
Source-available (FSL-1.1-ALv2)
GET STARTED

Ready for your security review

We built RootCX for environments where security is not optional. Start a project, or talk to our team about your requirements.

RootCX

Build secure, AI-powered apps on top of your existing systems, without touching your core.

Book a demo

Product

  • AI Agents
  • Internal Apps
  • Integrations
  • App Library
  • Infrastructure
  • Security

Solutions

  • Supply Chain
  • Fleet & Assets
  • Financial Services
  • Healthcare
  • Retail & DTC

Company

  • Documentation
  • Pricing

© 2026 RootCX Inc. All rights reserved.

Privacy PolicyTerms of Service
All systems operational