Skip to main content

01. Platform Overview & Vision

CONNEX Cloud OS is not a simple conversational bot. It is an Agentic Cloud Workspace Operating System built for strategic enterprise decision-making and knowledge assetization:
  • Full-Stack Cloud OS Capabilities: Seamlessly integrates a virtual file system (VFS), real-time collaboration canvas (CoWorx), agent studio, and knowledge engine (Brain X).
  • Deterministic Security Boundaries: Statutory privacy compliance (Korea PIPA, US CCPA) and session security are strictly hardcoded with zero tolerance for probabilistic AI conjecture.
  • Real-Time Knowledge Synchronization: Synchronizes with Git repositories and the Mintlify global documentation portal to eliminate documentation obsolescence.
CONNEX provides dual-spectrum intelligence spanning executive leadership to technical researchers:
  • Executives & Strategy Teams: High-density ERP/CRM/BI synthesis, M&A due diligence, legal/tax brief drafting, and strategic decision support.
  • R&D & Engineering Teams: Dynamic tool-chaining across 108+ APIs, MCP agent integration, and autonomous code synthesis.
  • Personal & Family Life: Children’s educational roadmaps, family travel logistics, and intelligent day-to-day assistance.

02. Data Sovereignty & Security

CONNEX implements strict physical database segregation across geographic regions:
  • Republic of Korea Jurisdiction (PIPA): All identifiers, session tokens, and profiles for Korean users reside exclusively in the accounts-kr Firestore database in Seoul (asia-northeast3).
  • US & Global Jurisdiction (CCPA/GDPR): Data for international users resides in the accounts-us Firestore database in Iowa (us-central1).
  • Zero Cross-Contamination: Intercontinental loop queries are permanently banned. Requests route directly to the single database corresponding to the user’s home_country.
To protect cross-domain single sign-on (SSO) transitions against replay attacks, CONNEX uses a single-use ticket handshake:
  • Issuance: The identity authority generates a cryptographically secure UUIDv4 ticket mapped in Redis with a 120-second TTL.
  • Immediate Burning: The ticket is permanently deleted from Redis upon its first exchange request (/api/v1/auth/exchange).
  • Replay Protection: Re-submitting an already used ticket results in immediate rejection, completely mitigating packet interception risks.

03. Global Infrastructure & Performance SLAs

CONNEX guarantees ultra-low-latency authentication and streaming performance globally:
  • Authentication SLA: Auth verification completes globally in under 300ms by embedding authorization claims directly into cryptographically signed JWT tokens.
  • Real-Time Bidirectional Streaming: ASGI thin orchestrators maintain zero-delay WebSocket and SSE pipelines.
  • GKE Gateway API: Traffic is routed through modern GKE L7 External Managed Gateways with Google Certificate Manager SSL termination.

04. Agentic AI & Citation Fidelity

CONNEX enforces strict citation fidelity filters across all document-grounded reasoning:
  • In-Text Section Citations: Responses reference source documents using explicit chunk citations ([ref:filename#section]).
  • Contingency Disclosure Banner: If an external data source fails and fallback search is engaged, a mandatory notice banner (⚠️ [Data Source Contingency Notice]) is displayed.
  • Deterministic Business Rules: Financial computations, statutory clauses, and role verifications are 100% hardcoded in Python, never delegated to LLM conjecture.

05. CoWorx Collaboration & Cloud VFS

CONNEX VFS operates an event-driven 3-tier cache invalidation and broadcast pipeline:
  • 7 Mutation Operations: Folder creation, upload, deletion, rename, move, copy, and clone trigger instant Redis L2 cache flushes.
  • SSE VFS_CHANGED Propagation: Broadcasts the VFS_CHANGED global event immediately, synchronizing file trees across all connected clients in 0ms.
  • Single Folder Badge Standard: Selecting folders transmits clean single directory badges without expanding hundreds of individual files on the frontend.

06. Identity, RBAC & Single Sign-On

No. The CONNEX platform stores zero user password hashes in its databases.
  • 100% Firebase Delegation: Credential verification, MFA, and cryptographic password handling are fully delegated to Google Identity / Firebase Authentication.
  • Decoupled Architecture: Core credentials reside exclusively within Google IAM infrastructure; Firestore stores non-credential enterprise profile metadata only.

07. Capital Efficiency & Token Economics

CONNEX enforces the Four Laws of Token Capital Allocation to maximize ROIC:
  • 1-Turn 1-Channel Precision Targeting: A 0.1s query planner targets the exact required tool instead of triggering wasteful multi-tool searches.
  • 5-Turn Budget Capping: All agent reasoning loops terminate within 5 turns to prevent infinite token-bleeding loops.
  • L1 Front-Door Gatekeeper: Basic metadata lookups and greetings are resolved in 0.1s at the low-cost L1 layer without invoking high-cost reasoning models.
  • 3-Tiered Caching: L1 Memory and L2 Redis return cached responses for recurrent queries, driving marginal token costs to zero.