How Konyx keeps a person in charge of every send, isolates each company, and records what happened.
AI reads and drafts; it never sends. Every RFQ and every purchase order waits for a named person who holds the permission to open it, review the exact email, acknowledge the review and press Send.
Related: One RFQ to all the vendors · Autonomous purchasing
Source: Engineering Action Plan — decision log, 15 Sep 2026 · Checked 26 September 2026 · Version 1 · control.person-presses-send
Drafting an RFQ and sending it are separate permissions, checked in the API on every request — not in the screen. An employee who cannot send escalates by design, not by convention; calling the endpoint directly is refused.
Related: Roles and permissions · An employee who may raise a request but not send an RFQ
Source: Engineering Action Plan — §3.1 · Checked 26 September 2026 · Version 1 · control.permissions-on-every-call
Every state change is written in the same transaction as the change itself, by the one function allowed to change a status, and the log is append-only at the database level. The trail cannot disagree with what happened because nothing else can write either.
Related: The activity log · Can we see who did what?
Source: Engineering Action Plan — §3.7 · Checked 26 September 2026 · Version 1 · control.append-only-audit
A vendor found on the web is never emailed until a person picks it and checks the address on the send screen. That one gate is the quality gate, the deliverability gate and the legal gate.
Related: Vendor discovery on the open web
Source: Engineering Action Plan — §3.4 · Checked 26 September 2026 · Version 1 · control.discovered-vendors-reviewed
Row-level security is forced on every tenant-scoped table and the application connects as a role that cannot bypass it. Two automated checks fail the build if a table lacks its policy or a query bypasses the scoped accessor, and a live test proves a cross-company read is refused. Konyx staff use the same permission wall, never a database console.
Related: How is our data kept separate from other companies'? · The shape of the system
Source: Engineering Action Plan — §3.1 · Checked 26 September 2026 · Version 1 · control.tenant-isolation
The Terms of Service and Privacy Policy are published at konyxai.com/terms and konyxai.com/privacy. Everyone signing in to the company app ticks a box agreeing to both, and the version each person agreed to, and when, is recorded against them and in the activity log.
The sign-in and activation forms refuse to go on without the box, and so does the API behind them. When the terms change, the next sign-in asks again.
Konyx does not sell personal information or use it for advertising. Google Analytics runs on the site and the company app only when switched on, with advertising features off; it receives page paths with record numbers blanked, counts and choices, and the person and company as internal codes — never names, emails or what anyone typed. It never runs on the vendor quote link, or when the browser sends Global Privacy Control.
- Terms of Service
- https://konyxai.com/terms
- Privacy Policy
- https://konyxai.com/privacy
- Recorded per person
- terms version agreed to
- when
Related: Each company is isolated in the database · Where does Konyx run? · Which AI models does Konyx use, and what sees our data?
Source: konyxai.com — /terms and /privacy · Checked 1 October 2026 · Version 1 · control.terms-and-privacy
Companies and their owners are created only by Konyx staff from the console, which emails the owner a temporary password. Nothing can be signed into that a human did not deliberately create, and every credential has one auditable origin.
Related: The shape of the system
Source: Engineering Action Plan — decision log, 15 Sep 2026 · Checked 26 September 2026 · Version 1 · control.no-default-accounts
One backend owns the database, the sessions, the permissions, email and AI, and cannot be reached without a key the browser never holds. The web applications are database-free: the browser calls their own backend, which forwards to the API with that key and the person's session. Sessions live in an httpOnly cookie; the token never appears in a response body.
Every route that can be abused is rate-limited in the database, so every instance sees the same count: sign-in, activation, RFQ sending, AI requests, web vendor search, the vendor quote link, imports and the rest. State changes are refused unless the request came from the application's own origin. Security headers are set on every response; secrets live in a managed secret store, not in code.
Related: Where does Konyx run? · Each company is isolated in the database
Source: Engineering Action Plan — decision log, 16 Sep 2026 · Checked 26 September 2026 · Version 1 · control.architecture
Each call to a model is recorded with who made it, which task and prompt version, and what it cost, and is shown per company and platform-wide. Each extracted field keeps its state, its evidence and the call that produced it, so the answer to why did it say that is always on file.
Related: What the AI does, and what it never does · Which AI models does Konyx use, and what sees our data?
Source: Engineering Action Plan — §3.8 · Checked 26 September 2026 · Version 1 · control.ai-provenance