Security & data handling
Last reviewed 9 October 2026 · Hexa Studio 0.8.0
In short
- Your PC talks to Microsoft directly. There is no Hexa Studio server between you and your data.
- Microsoft sign-in with OAuth 2.0 and PKCE; no passwords are stored, and the app can only do what your own account can do.
- Every write to an environment is shown as a diff or a row count and needs your confirmation first.
Architecture
Hexa Studio is a native Windows app built with Tauri: a Rust core and a WebView2 window. All requests to Microsoft are made from your PC. We run no backend, store no customer data and collect no telemetry, so there is nothing of yours on our side to leak.
The app window has no direct file-system access. Reading and writing files (exports, Flow task folders) goes through the Rust core, using locations you pick in a Windows dialog.
Sign-in and permissions
- Sign-in uses the OAuth 2.0 authorization code flow with PKCE in your normal browser, returning to a local loopback address on your PC. You type your password only on Microsoft's own sign-in page, and your organisation's MFA and Conditional Access policies apply as usual.
- The app uses delegated permissions: it acts as you, inside the environments and roles your account already has. It cannot see or change anything you can't.
- The refresh token is stored in Windows Credential Manager, protected by your Windows account. Access tokens live in memory only. Signing out deletes the stored token.
- Each project (one per tenant or customer) keeps its own sign-in, so accounts from different customers stay separate.
Data on your PC
| Data | Stored | Leaves your PC |
|---|---|---|
| Refresh token | Windows Credential Manager | Only to Microsoft, to renew access |
| Projects, environments, settings | %APPDATA%\CdsSqlStudio | No |
| Query history and UI preferences | App window local storage | No |
| Records, flows, web resources you open | Memory while shown; files only when you export | No |
| Flow task check-outs | A folder you choose (optionally a git repository) | Only if you share that folder |
The app connects to Microsoft sign-in, the Power Platform Global Discovery Service, the environments you open, and GitHub Releases for updates. Nothing else. See the Privacy Policy for details.
Guarded writes
Most of Hexa Studio only reads. Where it writes, it shows you exactly what will change first:
- Web resources: nothing is written until you have reviewed a side-by-side diff of the change. Before saving, the app checks a fingerprint of the current version; if someone else changed the file in the meantime, it stops and shows you the conflict instead of overwriting their work.
- Flow tasks: edited flows are compared step by step with the original and with the live cloud version, and checked for broken references (missing steps, uninitialised variables, unknown connections). A flow is deployed only after you mark it reviewed, and only to an environment you have tagged DEV.
- SQL:
INSERT,UPDATEandDELETEstatements first show how many rows will change and wait for your confirmation. - REST builder: read requests run in the app; create, update and delete requests are generated as code only, for you to run in your own tools.
Updates
Installers and updates are published on GitHub Releases and built by GitHub Actions from the public source. The built-in updater checks the signature of each update against a public key compiled into the app and refuses an update that doesn't match.
Current limits
We'd rather be clear about what isn't there yet:
- The Windows installer is not code-signed yet, so Windows SmartScreen may warn you on first install. Updates are signed, as described above.
- Hexa Studio is built by one person and has not had a third-party security audit or certification such as SOC 2.
- Data the app stores on your PC is protected by your Windows account and disk encryption, not by an extra app-level password.
Report a vulnerability
If you find a security problem, please email founder@hexastudio.com.vn with the steps to reproduce it and the version you tested (shown in Settings). Please don't open a public GitHub issue for it. We'll confirm we received it, keep you updated while we fix it, and credit you in the release notes if you'd like.