Security
Security and data isolation, built in from the start
Your manuals, schematics and service notes are some of your most valuable know-how. Here's how Fixxit keeps them yours: in the database, in the file system and inside the AI assistant itself.
Tenant isolation
Fixxit is a multi-tenant service, and isolation is part of the data model rather than an afterthought.
- One owner for every record. Every machine, document and conversation belongs to exactly one organization.
- Scoped access everywhere. Application code loads customer data only through tenant-scoped queries, so a request from one organization cannot address another organization's records.
- Separate libraries. Each organization's documents are stored in their own library folder, and the assistant's working state is kept per organization as well.
- Tested continuously. Our automated test suite exercises every API route under every role, including cross-tenant access attempts.
How the AI assistant is confined
Fixxit's assistant reads your library with a small set of tools. Every request runs inside a sandbox tied to the organization that asked:
- Read-only tools. The assistant can list, search and read documents. It has no tool that can write, change or delete files.
- Confined to your library. Every tool call is checked before it runs. Anything that would reach outside your organization's library (including through symbolic links) is refused.
- No arbitrary commands. The only programs it can run are Fixxit's own, pre-approved document tools, with plain arguments.
- No hidden configuration. No host settings or instructions are loaded into a session, and text in a question is never expanded into a file read.
- Sessions stay with their owner. A conversation can only be resumed by the user who started it, and session state is stored separately for each organization.
Accounts and access control
- Roles. Owners and admins manage machines and the document library. Members read the library and ask questions.
- Private conversations. Each conversation is visible only to the person who started it.
- Secure sessions. Session cookies are
HttpOnly,SameSite=LaxandSecurein production.
Application security
- Protection against cross-site requests. Write requests must be JSON or file uploads, and browser-flagged cross-site writes are refused.
- Safe rendering of answers. AI output is sanitized before it is displayed, and images are stripped, so instructions hidden in a document (prompt injection) cannot use an image link to send data out.
- Safe handling of uploads. Only PDFs, images and plain text are ever shown inline. Every other file type is served as a download, with content sniffing disabled and a sandboxing content security policy.
Your data and AI models
Fixxit uses Claude through Anthropic's commercial API. Under Anthropic's commercial terms, content sent through the API is not used to train its models by default. Your documents and conversations are used to answer your own team's questions, and nobody else's.
Answers are grounded in your documents and cite their sources, but they are still generated by an AI model. Fixxit reminds users to verify safety-critical steps, such as lockout/tagout, against the original document.
Hosting and transport
- All traffic to Fixxit is served over HTTPS, with HTTP Strict Transport Security.
- The service runs on managed cloud infrastructure, with customer libraries on dedicated storage volumes.
- This marketing website sets no cookies and loads no third-party trackers or analytics.
Going through a vendor security review? Get in touch and we'll work through your questionnaire with you.
Reporting a vulnerability
If you believe you've found a security issue in Fixxit, please email tanner.voutour@fixxit.ai with the details and steps to reproduce. Please give us reasonable time to investigate and fix the issue before disclosing it publicly. Our security.txt has the same contact details.