SECURITY · CONNECTORS
Connectors, governed.
How ABX reaches into your stack and why your credentials never leave your side.
Last updated · April 2026 · 3 min read
ABX doesn't stop at the report. It reaches into your ecosystem CRM, inbox, ad platforms, databases and executes. That reach is where every security review starts. So we built the architecture to answer it directly: four parties hold four responsibilities, and no single party can touch everything.
You authorize. Auth0 federates identity. Azure hosts. ABX executes, within the governance you define.
01 / THE OWNERSHIP MODEL
Who owns what
Four lanes. No overlap. No one party holds everything.
PARTY 01
You
- Your data, inside every connected system.
- The authorization, granted per connector, per scope.
- The Go / No-Go on every write, send, or publish action.
- The right to revoke at any time, from your own provider.
PARTY 02
Auth0
- OAuth app registrations, token refresh, API version handling.
- Identity federation across Google and Microsoft Entra ID.
- SOC 2 Type II compliant infrastructure with encrypted credential storage.
PARTY 03
Gieni ABX
- Intent-to-execution: planning and orchestrating the work.
- The approval architecture and the full audit log.
- Zero Trust orchestration, our workers carry no secrets.
PARTY 04
Microsoft Azure
- Hosting, West Europe (Azure region).
- Network isolation, TLS 1.3, Web Application Firewall.
- Disk-level encryption with Microsoft-managed keys.
02 / SECURITY MODEL
Five layers, so no single breach is enough
Security isn't a setting on top of ABX. It's the architecture underneath it.
01
Credentials never touch our database
OAuth tokens are securely managed via Auth0 and never stored in our database. ABX exchanges tokens on-demand, server-side, scoped to a single execution. If our database were breached, there would be no connector credentials to steal, they aren't there.
02
Zero Trust Workers
Our workers hold no database credentials, no OAuth tokens, no AI keys, no direct internet access. Each receives a short-lived, scoped session token that auto-expires. The blast radius of a compromised worker is one execution.
03
Two-Logic governance
Read and analyze actions run autonomously. Write, send, publish, and transact actions require explicit approval before execution. You delegate the work. You keep the decision.
04
Encrypted in transit, encrypted at rest, logged without exception
TLS everywhere. Azure disk encryption. Every execution produces a structured work log, what ABX did, what it read, what it sent, and exactly what you approved.
05
Revocation belongs to you
Disconnect inside ABX, or revoke the OAuth grant directly from Google, Microsoft, or any other provider. ABX loses access in real time. The governance doesn't depend on us being trustworthy, it depends on you holding the keys.
03 / COMPLIANCE
Swiss precision. European residency.
The facts your CISO, DPO, or procurement will ask for — on one page.
Hosting
Microsoft Azure · West Europe (Azure region)
Residency
European Union
Regulatory
GDPR, FADP aligned
Identity
Auth0 (supports Google, Microsoft Entra ID)
Model routing
Azure AI Foundry
Training on your data
No — never
"What Orderfox has built represents a significant advancement in autonomous execution that empowers humans to achieve more. Gieni ABX combines operational autonomy with enterprise-grade security and governance, making execution at scale both possible and trustworthy."
Andrew Reid · Commercial Partner Lead, Microsoft Switzerland
Featured on