01
Identity & sessions
Email verification, multi-factor authentication options, session visibility, and revocation controls protect account access.
Security & access controls
NexyFlow separates who can sign in, what each role may approve, and which actions connected systems may perform.
01
Email verification, multi-factor authentication options, session visibility, and revocation controls protect account access.
02
Employee, organization-admin, and platform-admin permissions are evaluated separately. Connecting a system never grants approval authority.
03
Organization context is checked on protected requests, with optional organization IP allowlists for approved deployments.
04
Administrators can manage retention and data-loss controls. Exact storage, residency, and backup options are confirmed for each deployment.
05
Sensitive administration requires a fresh step-up check and is kept separate from everyday employee access.
06
Security-relevant changes and blocked access attempts are written to organization-scoped audit records.
Two different trust questions
Identity, role, tenant, policy, approval scope, and connection authority are checked before a mutation is accepted.
Verifiable Results checks the connected system again and records evidence separately from the security boundary.
See result verificationSSO, IP allowlists, retention, backup, and regional hosting depend on the selected deployment. NexyFlow confirms the active controls during onboarding instead of implying that every option is enabled everywhere.