Nox

Partial

The Wealth Engine

https://nox.noxsoft.net ↗

AI-native management software that replaces human middle management. 120+ pages, 83 API routes. The capitalist engine that funds liberation.

Completion89%

24

Live

7

Partial

0

Stub

0

Missing

95/120

Pages

83/83

APIs

83%

Security

Features (31)

Core8/8 live

Task ManagementLive

AI-powered task creation, assignment, and tracking

Project ManagementLive

Project planning, milestones, and progress tracking

Goal / OKR ManagementLive

Objective and key result tracking across org

Meeting ManagementLive

Scheduling, agendas, transcription, and action items

Feedback SystemLive

Peer and manager feedback with AI analysis

Escalation ManagementLive

Issue escalation workflows with auto-routing

Standup ManagementLive

Async standups with AI summaries

Team & Org ManagementLive

Multi-org support with role-based access

Communication3/4 live

Chat & AI AssistantLive

Real-time chat with AI-powered assistant

NotificationsLive

Push and in-app notifications across all modules

MessagesLive

Direct and group messaging system

VoicePartial

Voice calls and audio features — partial implementation

Intelligence2/5 live

Analytics & ReportingLive

Dashboards, reports, and data visualization

PredictionsLive

AI-driven predictions for project timelines and risks

AutomationsPartial

Workflow automation engine — UI scaffolded, no backend

WorkflowsPartial

Visual workflow builder — UI only, no execution

AgentsPartial

AI agent framework — UI scaffolded, partial backend

Business3/3 live

Billing & SubscriptionsLive

Stripe-based subscription management with tiers

OnboardingLive

Admin and employee onboarding wizards

Digital Davos / NexusLive

Nox-to-Nox encrypted inter-org communication

HR5/7 live

Hiring & RecruitmentLive

Job postings, applicant tracking, and AI screening

Knowledge BaseLive

Org-wide knowledge management and search

ReviewsLive

Performance review cycles with AI summaries

GovernanceLive

Policy management and compliance tracking

Time OffLive

Leave requests, approvals, and calendar integration

PerformancePartial

Performance tracking and improvement plans — partially built

CompensationPartial

Compensation management and benchmarking — partially built

Operations3/4 live

PlaybooksLive

Standardized process playbooks for teams

FinanceLive

Budget tracking, expense management, and invoicing

JournalLive

Work journal and reflection system

IntegrationsPartial

Third-party integrations (Slack, GitHub, Linear) — scaffold only

Security

Security Checklist

4/6 passing
CheckStatus
CSRF ProtectionPass
Rate LimitingPass
Input ValidationPartial
Security HeadersPass
Auth / SessionPass
EncryptionPartial

Issues(15 open)

Critical

No CSRF protection on any mutation API routes

Resolved
Critical

Rate limiting only on 4/83 routes — open to abuse

Resolved
Critical

No input validation schemas on most API routes

Resolved
Critical

Missing Content Security Policy header

Resolved
Critical

No HSTS header configured

Resolved
High

No request size limits on file upload routes

Open
High

Admin routes lack additional authorization checks

Open
High

No audit logging for sensitive operations

Open
High

WebSocket connections not rate-limited

Open
High

No session invalidation on permission changes

Open
High

API keys stored in plain text in database

Open
High

No brute force protection on login attempts

Open
High

Org invitation tokens do not expire

Open
Medium

No output encoding on user-generated content

Open
Medium

Missing CORS restrictions on API routes

Open
Medium

No request logging for debugging and forensics

Open
Medium

Cookie flags missing Secure attribute in dev

Open
Medium

No error rate monitoring or alerting

Open
Medium

Database queries not parameterized in some routes

Open
Medium

No dependency vulnerability scanning in CI

Open

API Route Inventory

83

Total Routes

83

Rate Limited

120

Total Pages

95

Live Pages