Regixo docs
For the compliance team·Step 2 of 6 — Is it safe to sign?·see the whole journey ↗

Is it safe to sign with Regixo?

Your name goes on this record, and a regulator may one day ask you to stand behind it. So before you fill anything in, it is right to ask who Regixo is, where your record is kept, and what you are taking on trust. This page answers those questions plainly — including the ones where the honest answer today is “not yet”. Reviewing the record commits you to nothing; signing comes later, and only when you decide.

Land here from: Understand the record (what the record is), or the email your engineer forwarded. Ready to open the link itself? That is the next step.

Reviewing commits you to nothing Opening the link, reading the record, even filling in the legal calls — none of it signs anything. The record stays a DRAFT until a named person deliberately signs it. Nothing here asks for a card, and the draft is free forever. So you can answer every question below at your own pace.

Run the six checks on this deployment (the worked example)

Before the detail, walk one real deployment through all six checks — the portal in front of you, exactly as its trust page reports itself. The trust page counts its own gaps out loud (“3 of the claims below are not published. 1 protection is switched off.”), so the checks are concrete:

CheckWhat the trust page saysYour read
1 · Open itThe page loads and separates what you can verify yourself from what you take on the vendor’s word.Start here. The gaps are marked ✓ published · ○ not published · ✕ switched off — read them, don’t skim.
2 · Who? South East 1 OÜ — the registered company behind Regixo.Good. You have a named counterparty for the contract.
3 · Where? region not published on this deployment.Raise it. Ask the operator to confirm the hosting region in writing before you sign.
4 · Encrypted? encryption of stored records not enabled — plain text.Raise it. Resolve in writing before you upload anything sensitive or sign.
5 · Continuity / liability / timestampSealed record verifies offline ; liability cap and a qualified timestamp not yet published.Continuity needs no trust. Ask for the liability figure and the timestamp timeline.
6 · DecideSafe to review and fill today — that commits you to nothing. Put region, encryption and liability in writing before the signature.

The verdict on this deployment: review it now, sign it later — with a short, written list of items to resolve first. Every check below is one of those six, in full — what “good” looks like, what “raise it” looks like, and the exact action when an answer is not published.

Your engineer’s draft may reach you as a plain http:// link, sometimes on localhost — the shape a security-minded person is trained to distrust. Here is what is actually happening. A localhost link only works on the machine that made it; the link you receive points at the portal your engineering team runs — often their own machine, which is why the link can look local. The hosted portal, app.regixo.com, is the default once it is switched on; it is not yet.

You are not asked to install anything, and you never create a password: you prove it is you with a one-time link sent to your email, which is why there is no account to be phished. If a link ever looks wrong, the safe move is the same as always — confirm with the colleague who sent it before you open it.

1 · Open the trust page

How to open it: on the claim record, follow who is Regixo? → (top of the page); or go straight to /trust on the portal. It is a page that answers the vendor questions in full, written to be read by exactly the person about to sign. It separates the claims you can verify yourself from the ones you take on the vendor’s word — and, unusually, it counts its own gaps out loud: “3 not published, 1 switched off”. That candour is the point; it tells you precisely which items to raise. Read the whole page once before you form a view.

what you'll see — the portal’s “Who is Regixo?” page: what you take on trust, each marked ✓ published · ○ not published · ✕ switched off

What you take on our word

These are the claims you cannot check from outside. This is all of them, each with the document behind it where we have published one.

3 of the claims below are not published. 1 protection is switched off. Each one is marked in its section below. A blank means we have not published the document — not that the answer is being withheld.

Who runs this portal?

  • Confirmed: South East 1 OÜThe registered company behind Regixo — the entity you would name in a contract.

Where is your record kept?

  • Where the servers areNot publishedThe country or region this portal runs in — this deployment has not declared it. The agreement it serves commits to EU hosting: read the clause.
  • Encryption of stored recordsNot enabledThis portal stores records as plain text. Anyone who can read its database file can read what is in them. The agreement’s encryption clause is not yet in effect here — read the clause, and ask the operator before uploading.

2 · Who runs the portal?

You are about to sign a contract with whoever runs this portal, so the first question is whether there is a named legal entity to sign it with.

Good ✓A registered company is named. On this deployment the trust page reads South East 1 OÜ — the entity you would put in a contract — and it also appears on the data-processing agreement.
Raise itNo entity is named, or only “Regixo / a team” with no legal name. Then you have no counterparty. This is the one gap that should stop you, not just slow you.
If not publishedAsk the operator for the registered legal name and the DPA before you go further — the entity must appear on the contract you sign.

3 · Where is your record kept?

Your record holds the names of your tables and columns — confidential in themselves — so where the servers sit is a real question, especially under EU data-residency rules.

Good ✓The region is stated, and it is in the EU.
Raise itOn this deployment the region is ○ not published. The agreement commits to EU hosting; the running portal has not declared where it runs.
If not published → do thisAsk the operator to confirm the hosting region in writing before you sign; the DPA’s hosting clause is the reference. It does not stop you reading or filling the record — only signing.

4 · Is it encrypted right now?

Encryption at rest is a promise about the record as it sits on disk today, not a plan. Check the running state, not the agreement.

Good ✓The trust page says stored records are encrypted at rest.
Raise itOn this deployment it reads ✕ not enabled — storage is plain text, and the encryption clause is not yet in effect here. Anyone who can read the database file can read what is in it. Remember the metadata alone is sensitive: a table named patients_oncology leaks even with no rows behind it.
If switched off → do thisTreat it as a resolve-in-writing-before-you-sign item, and ask the operator before you upload anything sensitive.

5 · Continuity, liability and the timestamp

Three more items a careful reviewer checks. One needs no trust at all; two have an honest “not yet”, and each has a specific thing to ask for.

Continuity ✓Verifiable, no trust needed. A sealed record carries its own verifier and public key; anyone can check the signature offline, and you can export the evidence to keep. It verifies without Regixo — even if Regixo one day disappears. So a small-vendor worry does not put your signed record at risk.
Liability capNot yet published. The terms and liability wording are under legal review before the first paid signature. Ask for the current figure as part of your due diligence.
Signing timestampToday the signing time rests on the vendor’s clock — there is no qualified third-party timestamp behind it yet, and the seal says so on its own face. A qualified timestamp is planned; ask for the timeline.
Retention ✓An unclaimed upload is deleted after 90 days; a replaced record is erased after 30; a signed record is yours and is kept. Stated on the trust page.
Support / security contactOn this deployment both are ○ not published. Until they are, write via the colleague who forwarded the link, or regixo.com/contact.

What you can check without trusting anyone

Before you weigh the trust-me claims, note what needs no faith at all — the trust page lists these separately, and you can verify each yourself, today. These are the strong side of the ledger:

Regixo is licensed AGPL-3.0, but the source is not public yet — it goes public with the release. Until then you cannot read the scanner line by line, so it is not on this list.

6 · Decide — proceed, or write first

Now make the call. Ask these in order:

  1. Is a real legal entity named (check 2)? No → stop; you have no one to hold to the contract. This is the only check that blocks even reading.
  2. Does any ○ or ✕ touch your own risk before signing — region, encryption, liability? → write to the operator and get each answered in writing. These block the signature, not the review.
  3. Do the verifiable claims check out (offline-verifiable seal, published price)? Yes → proceed to review.

Proceed means open the record and start reviewing — which commits you to nothing (the record stays a DRAFT, and the draft is free forever). Write first means email the operator the specific ○/✕ items and hold the signature until they answer; keep this page as the checklist. You can do both at once: review now, resolve the written items before the signature.

What Regixo will not paper over The trust page names its own gaps — “3 not published, 1 switched off” — rather than hiding them. That candour is the point: it tells you exactly which items to raise before you sign. None of them stops you reading the record; some are worth an email to the operator before you put your name on it. A record is defensible because it is true, and that includes being true about the tool that made it.

How you know you’re done

You have finished this check when all of the following are true:

What your engineer already did — and what is theirs, not the vendor’s

The record reached you because someone on your engineering team ran Regixo against your own systems and forwarded the result — only structure left their machine, never a row of data. Anything about your data’s coverage (a system not yet scanned, a flag that looks wrong) is a question for them, not the vendor. The vendor questions are the ones on this page.