How Sixfold OS protects your data: delegated authentication, least-privilege access, per-module isolation, audit and governance records, encryption, and sub-processors.
Last updated: 4 July 2026
This document is a template provided for information only. It is not legal advice and not a certification. Any remaining placeholders in square brackets must be completed, and the whole text reviewed by qualified counsel, before it is relied upon.
Security is built into the architecture of Sixfold OS rather than added afterwards. Our controls are designed to align with the ISO/IEC 27001 information-security framework. Alignment with a framework is a design objective and is stated here for information; it is not itself a certification.
Identity is authenticated externally by Auth0 (Okta, Inc.) and single sign-on, and mirrored into Sixfold OS as minimal identity claims. Sixfold OS does not store user passwords. The authentication tenant is configured in the European region.
Data is isolated by tenant, by workspace, and by module namespace. Every governed resource carries a tenant and workspace envelope, and access is enforced against a resource boundary — a request whose access context does not match the tenant/workspace scope is rejected. Module data stays isolated within its namespace and is not shared across modules by default.
Governance actions produce durable records used for accountability and assessment, including policy acknowledgements, review approvals, and integrity-gate outcomes. Governance workflows enforce integrity gates (for example manipulation, cognitive-load, inclusivity, and telemetry-transparency checks) and steward approval before designated actions can proceed.
Traffic to the service is encrypted in transit using TLS. Session cookies are protected with a dedicated encryption key. Data at rest is protected by the encryption capabilities of our hosting and database providers. [Confirm specific at-rest encryption details with your infrastructure provider.]
We use a limited set of sub-processors to operate the service:
Authentication, session issuance, and single sign-on.
Application and database hosting.
Transactional email and support communications.
Any further processors are listed here and updated as the service evolves.
Each sub-processor is engaged under a data processing agreement. To request the current sub-processor list or report a security concern, contact admin@sixfoldux.com.
If you believe you have found a security vulnerability, please report it responsibly to admin@sixfoldux.com and allow us reasonable time to investigate and remediate before public disclosure.