OAuth and credentials
Each system is authorised with scoped OAuth or least-privilege API credentials, stored encrypted, rotatable and revocable one connection at a time.
System Architecture
The operating model the agents follow, the governance around them, how the system joins your existing stack, and which parts are ours versus a named third party.
System Overview
Agents capture need, timeline and budget in conversation, and score every lead on live signals — so only real opportunities move forward.
Qualified conversations are handed to the right next step automatically: a booked Free Strategy Audit, an outreach sequence, or a task for the owning human.
Agents work inside tight guardrails — they can't make claims, quote prices or commit your business without human approval. Positive replies and edge cases go straight to a person.
Every action is audit-logged and traceable, with daily briefings by email or Slack, so you always see what an agent did and why.
What Connects Them
Every connected system publishes its events onto one shared bus. Any event can trigger an AI workflow, and any workflow can call any agent. That is what makes the agents a system rather than six separate tools — a lead created in your CRM, a call answered by ARIA, a card charged in Stripe and a conversion fired by an ad platform all arrive in the same normalised shape, with the same identity resolution, permissions and audit trail behind them.
Each system is authorised with scoped OAuth or least-privilege API credentials, stored encrypted, rotatable and revocable one connection at a time.
Per system and per object: read-only, write with approval, or write automatically. Defaults are read-only until you widen them.
Inbound webhooks are signature-verified and de-duplicated; outbound webhooks let your own systems subscribe to Xiilio events.
Failed calls retry with exponential backoff and jitter, respect vendor rate limits, and stop at a defined ceiling rather than hammering an API.
Anything that cannot be delivered goes to a dead-letter queue, is surfaced in the command centre, and is replayable once the cause is fixed. Nothing is silently dropped.
Every event, workflow run, agent action and configuration change is logged with timestamp, actor, inputs and before/after values, and is exportable.
Who can view, edit, approve, execute or connect is set by role. Approval rights are separate from build rights.
Field-level mapping between systems with type coercion, transformation rules and one authoritative source per field, changeable without engineering work.
A searchable timeline of every event and every workflow it triggered, filterable by system, record, agent or outcome.
Workflows are versioned, diffable and roll-backable. Each run records the version it executed, so past behaviour stays explainable.
Any step can be marked approval-required, with a named approver, a timeout and an escalation path if nobody responds.
Event coverage depends on what each vendor's API and webhook surface exposes and on the permissions you grant. Workflows described here are configuration examples, not guaranteed outcomes.
Governance Layer
These are the same controls published in full on the Responsible AI centre and the security disclosure, including the limits of each one.
Autonomy without a human decision point is how automated systems cause commercial damage at speed.
Oversight is only as good as the reviewer. Where you enable auto-execute, actions happen without a person seeing them first — that is your decision to make, and the caps are yours to set.
An agent with broad system access can do broad damage, quickly, without malice.
Permissions govern what the platform can do inside connected systems. They cannot restrict what those systems then do with a legitimately authorised action.
If you cannot reconstruct why an automated system did something, you cannot defend it to a regulator, a client, or your own board.
Logs capture what the platform did and on what basis. They are not a certified immutable ledger, and retention follows the periods published on the Security page.
The value of an AI system is decided by what it does at the edge of its competence.
Escalation hands the matter to your team or ours. Response times depend on the humans available; we do not offer a 24/7 answering guarantee.
Integration Layer
NEXUS is the layer every other agent runs on. NOVA, ARIA, HERALD, SENTINEL and CORTEX do not each hold their own private copy of your data — they read and write through NEXUS, so one record, one identity and one audit trail run across the whole stack. Availability of any given system depends on that vendor's API and your plan with them.
Conflicts are resolved by a rule you set, not by whichever system wrote last.
The same person or company across CRM, billing, ads and email is matched to one record instead of five.
A retried sync does not create duplicate contacts, tasks or deals.
Vendor API limits are respected and queued through, rather than failing a sync mid-run.
A failed sync is queued, surfaced and re-runnable once the cause is fixed. Nothing is silently dropped.
Every read, write, mapping change and agent action is logged with timestamp, actor and before/after values.
Each connection uses least-privilege credentials, revocable independently, with no shared master key across systems.
Connections can be disconnected at any time and the systems keep working — NEXUS coordinates your tools, it does not hold them hostage.
Connector availability depends on each vendor's API and your own plan with them. Where a native connector is not available, NEXUS uses documented APIs or webhooks — we will tell you which before you buy, not after.
Full NEXUS connector list →What's Ours, What Isn't
We would rather under-claim here than have a buyer discover a gap later. So, plainly:
Xiilio does not train or fine-tune its own foundation models, and does not offer self-hosted or private model deployment. Every inference call goes to a third-party provider.
Xiilio is a browser-based application with a managed Postgres backend and serverless functions. There is no Xiilio-operated hardware.
The named models behind the agents, so you can assess them yourself.
Every third party that can process customer data on our behalf. If a vendor is not on this list, it does not have your data.
We'll take a technical buyer through the architecture against your own stack, connector by connector.
We use a single first-party cookie to remember your currency and consent choice. Page-view analytics are sent to our own servers — no third-party trackers, no profiling. See our Privacy Policy.