Isolation
Hydrix provisions each site as its own logical environment with isolated identity and data boundaries.
Security
This page gives clients a high-level summary of the default security posture for Hydrix-managed sites.
super-admin, admin, and user rolesHydrix provisions each site as its own logical environment with isolated identity and data boundaries.
Sites are delivered through managed AWS edge and storage services with HTTPS enforcement and WAF coverage.
Protected routes use site-scoped Cognito authentication and role-based access controls. MFA/2FA is planned work and is not part of the current default site authentication experience.
Standard deployments use private storage patterns and AWS-managed encryption features for stored data.
When Hydrix manages email for a site, the domain is configured with SPF, DKIM, DMARC, and SES-verified domain controls.
CloudWatch, CloudTrail, CloudFront, and WAF logging support alerting, operational review, and auditability.
Hydrix secures the managed infrastructure baseline. Clients remain responsible for:
Use this page as the first-pass trust overview. For project-specific review, pair it with implementation details, operational documentation, and direct security review as needed.