1. Overview
We take the security of our customers' data seriously. This page explains the controls and processes XOVO Technologies uses to protect information across our products, services, and internal operations.
2. Data Protection
- Encryption in transit (TLS 1.2+) and at rest (AES‑256).
- Least‑privilege, role‑based access with MFA for administrators.
- Secrets stored in managed vaults; keys rotated regularly.
3. Application Security
- Secure SDLC with peer review and automated CI checks.
- Dependency and container scanning for known CVEs.
- OWASP Top 10 controls for auth, validation, and session management.
4. Infrastructure
- Network segmentation with restricted ingress and firewalls.
- Centralized logging, alerting, and 24/7 monitoring.
- Encrypted backups and tested disaster recovery procedures.
5. Compliance
We align our controls to recognized frameworks and follow regional data protection regulations as required by customer engagements. Contact us for specific compliance documentation and DPAs.
6. Vulnerability Disclosure
If you believe you have found a security issue, please notify us at contactus@xovotechnologies.com. We will investigate promptly and appreciate responsible disclosure.
7. Incident Response
We maintain an incident response process covering triage, containment, eradication, and post‑mortem review. Customers are notified without undue delay if their data is impacted, consistent with contractual and legal obligations.