
Platform
Enterprise-Grade Controls, Your Domain, and an Open Door for AI Agents
Roles, row-level security, encryption, custom domains, and an MCP server with OAuth 2.1.
In Short
What Is Security, Platform & MCP in IFX Hub?
IFX Hub enforces row-level security on every record, per-module view/add/edit/delete permissions, and project-scoped access. Third-party secrets are encrypted with AES-256-GCM, every change is written to an append-only activity log, and a built-in MCP server lets approved AI agents use the hub over OAuth 2.1.
- Roles & Permissions
- Project-Scoped Access
- Row-Level Security
- Encryption
Security, Platform & MCP
Your IFX Hub · Platform
Roles & Permissions
View, add, edit, and delete permissions per module. A person can hold different roles in different workspaces.
Project-Scoped Access
Give a user all projects or specific ones; contractors see only projects they have tasks on.
Row-Level Security
Enforced everywhere — including assistant and MCP calls, which run as the calling person.
Encryption
Third-party credentials are encrypted with AES-256-GCM.
Audit Trail
An append-only activity log of every create, update, and delete.
10 capabilities, on the same records as every other module.
Capabilities
What Security & Platform Does
The building blocks of this module — shaped around your own fields, statuses, and workflows when we build your hub.
Roles & Permissions
View, add, edit, and delete permissions per module. A person can hold different roles in different workspaces.
Project-Scoped Access
Give a user all projects or specific ones; contractors see only projects they have tasks on.
Row-Level Security
Enforced everywhere — including assistant and MCP calls, which run as the calling person.
Encryption
Third-party credentials are encrypted with AES-256-GCM.
Audit Trail
An append-only activity log of every create, update, and delete.
Hardened Integrations
Webhooks verify signatures and fail closed; scheduled jobs refuse to run without a secret.
MCP Server
Your hub as a tool for AI agents: scoped API keys and OAuth 2.1 with dynamic client registration, PKCE, and refresh-token rotation.
Workspaces & Domains
Workspaces on subdomains, verified custom domains, a workspace switcher, and dedicated single-tenant deployments.
Staff SSO
Short-lived signed tokens let your staff open a client's app already signed in — every launch is logged.
Infrastructure Tracking
Daily Vercel and GitHub sync links each client's projects and repositories to their CRM record.
Works With
The Services Behind Security & Platform
These connections are part of the product. Each hub connects its own accounts, and credentials are encrypted with AES-256-GCM.
Supabase
Vercel
GitHub
- MMCP
How It Connects
Security & Platform Shares Its Records With
Nothing syncs between these modules because they're the same system — one record, one login, one place to change it.
FAQ
Questions About Security, Platform & MCP
What is an MCP server, and why does IFX Hub have one?
MCP (Model Context Protocol) is an open standard that lets AI assistants use software as a tool. IFX Hub's MCP server lets approved agents — like Claude — read and act in your hub over OAuth 2.1, with the same permissions as the person who authorized them.
Is each client's hub isolated?
Yes. Every IFX Hub is its own instance at its own address, with row-level security on every record. Dedicated single-tenant deployments are available.
Security & Platform in Your Hub
See Security & Platform Running on Your Data
Book a discovery call and we'll show you this module shaped around your fields, workflows, and statuses — and what else your hub should include.