Skip to main content
Security Statement

Customer-Facing Security Overview

This page summarises Xpitro's current security approach for prospects and customers.

Effective date: July 19, 2026. This statement is an overview of platform security principles and operational intent, not a representation that every control is implemented identically in every environment or plan.

Secure By Default

Xpitro is designed around least privilege, tenant isolation, auditable operations, and controlled secret management.

Protected Access

Authenticated access, role-based permissions, and scoped platform boundaries are used across customer and operator surfaces.

Operational Controls

The platform architecture includes monitoring, backup, restore, disaster recovery, and secret rotation procedures.

Shared Responsibility

Customers still control user administration, endpoint hygiene, permission assignment, and validation of AI-assisted outputs.

Security Statement

Xpitro's security model is grounded in architectural boundaries, operational auditability, and controlled change rather than marketing-only claims.

Security Principles

Xpitro is designed around least privilege, tenant isolation, secure-by-default infrastructure patterns, auditable operations, controlled secret management, and monitored recoverable runtime behaviour.

Access Control

Xpitro uses authenticated access, role-based access control, and scoped platform boundaries for customer users, customer portal users, and internal operators.

Secrets And Runtime Security

Production secrets are intended to be managed through controlled secret-management processes rather than committed source configuration. Stored secrets are not exposed back to browser clients after submission.

Data Protection

Where Xpitro processes customer personal data on behalf of customers, the DPA governs processor obligations. Where Xpitro acts as controller for website, account, marketing, or support data, the Privacy Policy applies.

Vulnerability And Incident Management

Xpitro maintains security review, vulnerability management, and incident-response processes appropriate to the product stage and deployment model.

What This Page Intentionally Does Not Claim

  • Specific certifications unless separately confirmed and published.
  • Uniform SLAs or incident response timings across every environment and plan.
  • Provider-specific hosting details as the source of trust.

Security Contact

Security questions, procurement requests, and responsible disclosure contacts should be directed to:

security@xpitro.com

Need A Security Review?

We can provide a product walkthrough, commercial materials, and the right follow-up path for customer diligence.