Xelium OneXelium One
PlatformModulesSolutions
  • Product TourSee Xelium One screen by screen
  • Security & trustHow your data is protected
  • Founder's visionWhy we are building Xelium One
  • FAQsAnswers to common questions
  • All resourcesGuides, pricing and more
Pricing
Product TourSign inGet started
  • Platform
  • Modules
  • Solutions
  • Pricing

Resources

  • Product Tour
  • Security & trust
  • Founder's vision
  • FAQs
  • All resources
Sign inGet started

Security & trust

Built to keep your organisation's data separate and accountable

These are the protections built into Xelium One today. We describe what is implemented and working — nothing more.

Report a security concern

What is in place today

Each organisation kept separate

  • Every record belongs to one organisation, and the database itself enforces that separation — not just the screens.
  • The organisation for each request is decided on the server from your signed-in session, never from what the browser sends.

Access checked on the server

  • Roles (owner, administrator, HR, manager, recruiter, finance, employee) decide what each person can see and do.
  • Every request is checked on the server. Hiding a menu is never the only protection.
  • Module access follows your organisation's subscription; a lapsed module becomes read-only and nothing is deleted.

Secure sign-in

  • Sign-in is handled by Supabase Auth.
  • New accounts confirm their email address before they can set up an organisation.
  • Passwords must be at least 12 characters.
  • You can sign in with a one-time email link instead of a password.

A history you can trust

  • Changes to people, roles, policies, attendance and money are recorded in an audit history.
  • Actions by Xelium Labs platform staff are recorded in a separate platform audit history, and platform changes ask for a reason.
  • Corrections never overwrite the original: an attendance correction or a voided invoice keeps the original record alongside the change.
  • Approvals are separated: people can't approve their own requests, offers or timesheets.

Separate from other Xelium Labs products

  • Xelium One is its own system. Other Xelium Labs products, such as GyaniX, are separate products with separate data.

Certifications

We don’t claim certifications we haven’t obtained.

Xelium One does not hold third-party security certifications today. If your organisation needs specific assurances, talk to us and we’ll answer honestly about what is and isn’t in place.

Responsible disclosure

If you believe you have found a security issue in Xelium One, please tell us privately so we can fix it.

  • Email us with a description of the issue and the steps to reproduce it.
  • Please don’t access, change or delete data that isn’t yours, and give us reasonable time to respond before sharing details.
Send a security report

info@xeliumlabs.com

Questions about data and access? See the FAQs or the Xelium One Core module.

See how Xelium One would fit your organisation.

Take the Product Tour, pick the modules you need, then get started or talk to us.

Get startedProduct TourBuild your Xelium One
Xelium OneXelium OneA Xelium Labs product

One Business. One Platform. People. Operations. Intelligence. Connected.

Platform

  • Explore the platform
  • All modules
  • Solutions
  • Build your Xelium One
  • Pricing

Modules

  • Xelium One Core
  • Xelium Pulse
  • Xelium Talent
  • Xelium CRM
  • Timesheets
  • Revenue
  • Incentives
  • Invoicing
  • Reports
  • Xelium Vendor (coming soon)

Resources

  • Product Tour
  • Security & trust
  • Founder's vision
  • FAQs
  • All resources

Company

  • Xelium Labs
  • Careers pages
  • Talk to us
  • Sign in
  • Get started
Xelium One · A Xelium Labs product