Loading RoomHex

Who gets into a room, and who decided

Nobody reaches a RoomHex session by holding the address. An administrator creates the account, a host approves the person at the door, and the host keeps control while the session runs.

  1. An administrator creates the account
  2. The person asks to enter the room
  3. The host admits or refuses them
  4. The host can mute or remove anyone
  5. The room closes and the log stays

Your conversations and records stay with you

RoomHex is self-hosted end to end, with no paid third-party service. Your conversations, media, and records stay where your team puts them. There is no public signup: an administrator creates each account after reviewing the request. Defaults stay conservative and administrators review access on a regular basis.

The protections already in place

These settings govern who can enter a session and how the platform behaves when it is under load.

Host approval for every session

A person joins a session after the host or an administrator approves the request. Someone without that approval does not reach the room.

Behaviour under heavy load

Rate limits and load controls keep a busy period, or an unwanted flood of traffic, from disrupting the people already in a session.

Conservative, secure defaults

When a security setting is missing or unclear, access stays closed. The cautious option is the default in every case of doubt.

Browser protections

The pages RoomHex serves are locked down in the browser. That cuts common web attacks and keeps the surface someone could abuse small.

Error messages shown to users

When something fails, the user sees a short, general message. Internal detail stays in the server logs, where it gives no clue to someone probing the system.

Controls for policy and accountability

These controls cover who administers what, which content a person may open, and what gets logged. Your own staff operate all of them.

ControlWhat it covers
Role-based and delegated administrationA person's role sets what they can open and change. Owners hand parts of the administration to specific staff, so the whole organisation does not share one level of access.
Branch permissionsYour organisation's own rules decide who can join. Each branch has its own permissions and works within the policy the organisation set for it.
Content access policiesAn access policy is attached to shared content. It names who may view or use the material, in line with the rights that apply to it.
Audit logging and evidence-aware exportsMeaningful actions are written to an audit log, and an administrator can export that log in a form suitable for presenting as evidence.
Data minimizationEach feature collects and stores only the fields it needs for the task. Less sensitive information is held, so there is less to protect.
Privacy and retention controlYour administrators set the privacy options and the retention period for each kind of data. They can change how long records are kept at any time.