Is it safe to sign with Regixo?
Your name goes on this record, and a regulator may one day ask you to stand behind it. So before you fill anything in, it is right to ask who Regixo is, where your record is kept, and what you are taking on trust. This page answers those questions plainly — including the ones where the honest answer today is “not yet”. Reviewing the record commits you to nothing; signing comes later, and only when you decide.
Land here from: Understand the record (what the record is), or the email your engineer forwarded. Ready to open the link itself? That is the next step.
- Open the trust page — the portal’s “Who is Regixo?” page, written for exactly this moment. (how ↓)
- Who runs the portal? — a named legal entity, or no counterparty at all. (check ↓)
- Where is your record kept? — the region it runs in. (check ↓)
- Is it encrypted right now? — at rest, on this deployment, today. (check ↓)
- Continuity, liability, timestamp — what survives if Regixo disappears, the liability cap, the signing clock. (check ↓)
- Decide — proceed to review, or write to the operator first. (decide ↓)
Run the six checks on this deployment (the worked example)
Before the detail, walk one real deployment through all six checks — the portal in front of you, exactly as its trust page reports itself. The trust page counts its own gaps out loud (“3 of the claims below are not published. 1 protection is switched off.”), so the checks are concrete:
| Check | What the trust page says | Your read |
|---|---|---|
| 1 · Open it | The page loads and separates what you can verify yourself from what you take on the vendor’s word. | Start here. The gaps are marked ✓ published · ○ not published · ✕ switched off — read them, don’t skim. |
| 2 · Who? | ✓ South East 1 OÜ — the registered company behind Regixo. | Good. You have a named counterparty for the contract. |
| 3 · Where? | ○ region not published on this deployment. | Raise it. Ask the operator to confirm the hosting region in writing before you sign. |
| 4 · Encrypted? | ✕ encryption of stored records not enabled — plain text. | Raise it. Resolve in writing before you upload anything sensitive or sign. |
| 5 · Continuity / liability / timestamp | Sealed record verifies offline ✓; liability cap and a qualified timestamp not yet published. | Continuity needs no trust. Ask for the liability figure and the timestamp timeline. |
| 6 · Decide | — | Safe to review and fill today — that commits you to nothing. Put region, encryption and liability in writing before the signature. |
The verdict on this deployment: review it now, sign it later — with a short, written list of items to resolve first. Every check below is one of those six, in full — what “good” looks like, what “raise it” looks like, and the exact action when an answer is not published.
The link looks like phishing — is that safe?
Your engineer’s draft may reach you as a plain http:// link, sometimes on
localhost — the shape a security-minded person is trained to distrust. Here is what is
actually happening. A localhost link only works on the machine that made it; the link
you receive points at the portal your engineering team runs — often their own machine, which is
why the link can look local. The hosted portal, app.regixo.com, is the default once it is
switched on; it is not yet.
You are not asked to install anything, and you never create a password: you prove it is
you with a one-time link sent to your email, which is why there is no account to be phished.
If a link ever looks wrong, the safe move is the same as always — confirm with the colleague who
sent it before you open it.
1 · Open the trust page
How to open it: on the claim record, follow who is Regixo? → (top of the page); or go
straight to /trust on the portal. It is a page that answers the vendor questions in full,
written to be read by exactly the person about to sign. It separates the claims you can
verify yourself from the ones you take on the vendor’s word — and, unusually, it
counts its own gaps out loud: “3 not published, 1 switched off”. That candour is the point; it
tells you precisely which items to raise. Read the whole page once before you form a view.
What you take on our word
These are the claims you cannot check from outside. This is all of them, each with the document behind it where we have published one.
Who runs this portal?
- Confirmed: South East 1 OÜThe registered company behind Regixo — the entity you would name in a contract.
Where is your record kept?
- Where the servers areNot publishedThe country or region this portal runs in — this deployment has not declared it. The agreement it serves commits to EU hosting: read the clause.
- Encryption of stored recordsNot enabledThis portal stores records as plain text. Anyone who can read its database file can read what is in them. The agreement’s encryption clause is not yet in effect here — read the clause, and ask the operator before uploading.
2 · Who runs the portal?
You are about to sign a contract with whoever runs this portal, so the first question is whether there is a named legal entity to sign it with.
| Good ✓ | A registered company is named. On this deployment the trust page reads South East 1 OÜ — the entity you would put in a contract — and it also appears on the data-processing agreement. |
|---|---|
| Raise it | No entity is named, or only “Regixo / a team” with no legal name. Then you have no counterparty. This is the one gap that should stop you, not just slow you. |
| If not published | Ask the operator for the registered legal name and the DPA before you go further — the entity must appear on the contract you sign. |
3 · Where is your record kept?
Your record holds the names of your tables and columns — confidential in themselves — so where the servers sit is a real question, especially under EU data-residency rules.
| Good ✓ | The region is stated, and it is in the EU. |
|---|---|
| Raise it | On this deployment the region is ○ not published. The agreement commits to EU hosting; the running portal has not declared where it runs. |
| If not published → do this | Ask the operator to confirm the hosting region in writing before you sign; the DPA’s hosting clause is the reference. It does not stop you reading or filling the record — only signing. |
4 · Is it encrypted right now?
Encryption at rest is a promise about the record as it sits on disk today, not a plan. Check the running state, not the agreement.
| Good ✓ | The trust page says stored records are encrypted at rest. |
|---|---|
| Raise it | On this deployment it reads ✕ not enabled —
storage is plain text, and the encryption clause is not yet in effect here. Anyone who can
read the database file can read what is in it. Remember the metadata alone is sensitive: a table
named patients_oncology leaks even with no rows behind it. |
| If switched off → do this | Treat it as a resolve-in-writing-before-you-sign item, and ask the operator before you upload anything sensitive. |
5 · Continuity, liability and the timestamp
Three more items a careful reviewer checks. One needs no trust at all; two have an honest “not yet”, and each has a specific thing to ask for.
| Continuity ✓ | Verifiable, no trust needed. A sealed record carries its own verifier and public key; anyone can check the signature offline, and you can export the evidence to keep. It verifies without Regixo — even if Regixo one day disappears. So a small-vendor worry does not put your signed record at risk. |
|---|---|
| Liability cap | Not yet published. The terms and liability wording are under legal review before the first paid signature. Ask for the current figure as part of your due diligence. |
| Signing timestamp | Today the signing time rests on the vendor’s clock — there is no qualified third-party timestamp behind it yet, and the seal says so on its own face. A qualified timestamp is planned; ask for the timeline. |
| Retention ✓ | An unclaimed upload is deleted after 90 days; a replaced record is erased after 30; a signed record is yours and is kept. Stated on the trust page. |
| Support / security contact | On this deployment both are ○ not published. Until they are, write via the colleague who forwarded the link, or regixo.com/contact. |
What you can check without trusting anyone
Before you weigh the trust-me claims, note what needs no faith at all — the trust page lists these separately, and you can verify each yourself, today. These are the strong side of the ledger:
Regixo is licensed AGPL-3.0, but the source is not public yet — it goes public with the release. Until then you cannot read the scanner line by line, so it is not on this list.
- A signed record proves itself. The seal carries its own verifier and public key; the signature checks offline, without contacting Regixo. What you cannot check yet is the key’s provenance: the production key-signing ceremony has not run, so today’s signing key is provisional. Ask for written confirmation that it has run before you sign.
- The price is on the page. Every plan and figure is printed on the payment screen — there is no “contact us for pricing”.
6 · Decide — proceed, or write first
Now make the call. Ask these in order:
- Is a real legal entity named (check 2)? No → stop; you have no one to hold to the contract. This is the only check that blocks even reading.
- Does any ○ or ✕ touch your own risk before signing — region, encryption, liability? → write to the operator and get each answered in writing. These block the signature, not the review.
- Do the verifiable claims check out (offline-verifiable seal, published price)? Yes → proceed to review.
Proceed means open the record and start reviewing — which commits you to nothing (the record stays a DRAFT, and the draft is free forever). Write first means email the operator the specific ○/✕ items and hold the signature until they answer; keep this page as the checklist. You can do both at once: review now, resolve the written items before the signature.
How you know you’re done
You have finished this check when all of the following are true:
- You have read the whole trust page, not skimmed it — every ✓, ○ and ✕.
- You have a written answer or an open action for each ○ (not published) and ✕ (switched off).
- You know which items are blockers before signing (a named entity, region, encryption, liability) and which you can carry (support address).
- You have decided: proceed to review, or write to the operator first — or both.
The record reached you because someone on your engineering team ran Regixo against your own systems and forwarded the result — only structure left their machine, never a row of data. Anything about your data’s coverage (a system not yet scanned, a flag that looks wrong) is a question for them, not the vendor. The vendor questions are the ones on this page.