Enterprise security built in

SAML SSO, domain verification, encryption at rest and in transit, and role-based access control.

SSO & SAML 2.0

Connect your identity provider — Okta, Azure AD, Google Workspace, or any SAML 2.0 compatible IdP. SP-initiated and IdP-initiated flows supported.

  • • SAML 2.0 Service Provider with signed AuthnRequests
  • • OIDC support for Google, Microsoft, and GitHub
  • • Domain verification via DNS TXT record
  • • Enforce SSO policy for verified domains
  • • JIT user provisioning and IdP group → role mapping

Encryption

All data is encrypted in transit (TLS 1.3) and at rest. API keys are hashed with bcrypt. Session tokens are signed and httpOnly.

Access control

Role-based access with admin, member, and viewer roles. Org-level isolation ensures your telemetry data is never accessible to other organizations.

Infrastructure

Refrax runs on Hetzner infrastructure in the EU. Data residency in EU data centers. Regular security updates and dependency patching.