We host things.
We pay people.
Phylex is a small hosting provider with a stubborn opinion about two boring things: infrastructure and payroll. We believe both should be transparent, auditable, and humane — and that there is no good reason for either to be otherwise.
/ 01 — Story
How this portal came to exist.
Every growing company arrives at the same Tuesday morning: somebody on Telegram is asking why their payout is late, somebody else can't find the CRM password, and the only spreadsheet that matters has nineteen tabs.
We hit that Tuesday in autumn 2024. By Wednesday we had a list of complaints long enough to be embarrassing. By the end of the month we had decided to build the thing we wished existed.
The result is intentionally small. There is no goal of making this a SaaS. It serves Phylex; it serves the people who work for Phylex; that's it. If someone else copies it, great — we'll send the schema.
What we tried not to copy from the back-office software we'd used: the gatekeeping, the modal-dialog hell, the assumption that "HR" is a different species from the rest of the company. Curators here are engineers. Engineers here approve their teammates' payouts. Everyone reads the ledger.
/ 02 — Values
The handful that actually drive decisions.
Not the full poster-on-the-wall list — the ones we've had to defend, in writing, when somebody (rightly) pushed back.
/ 03 — Money
How we think about money.
Salary money is yours the moment it's accrued. You can withdraw it to your bank, your card, or a crypto wallet — whichever rail fits your country and your patience.
Internal money is a voluntary holding spot: same currency, no fees, instant. Move salary into internal to pay your own Phylex hosting bills, or to cover a teammate's server. You can always withdraw it back out.
We don't process card payments ourselves and we don't custody crypto on your behalf. Every withdrawal is a manual transfer made by a named finance operator, who attaches the receipt before the request can be closed. The workflow makes shortcuts harder than the right path.
/ 04 — Data
How we think about data.
Card numbers, IBANs, crypto addresses, recovery phrases — these are encrypted with AES-256-GCM before they hit our database. Two independent keys, blast-radius isolated. A database dump without the keys is useless.
Reading any sensitive value, even by an admin, requires a written reason. That reason is part of an immutable audit log. We'd rather make the right thing convenient and the wrong thing visible than ask people to be saints.
AES-256-GCM
Authenticated encryption for all sensitive fields
argon2id
Passwords hashed at OWASP 2024 baseline
Audit log
Append-only; every reveal carries a reason
/ 05 — FAQ
The questions everyone asks.
That's the whole pitch.
Sound like a workplace you'd like to spend time in? Start an application.