Every platform we ship carries the same security posture we run our own business on. Here's what that means in practice.
TLS everywhere, automatic certificate management, and HTTPS-only policies on every property we deploy.
Role-based permissions, scoped API keys, and owner-only surfaces. People and services get the access they need and no more.
Privileged actions are logged: who did what, to which record, from where. Accountability is a feature, not a forensics project.
Production errors are captured, categorized, and surfaced to operators, so incidents get found by monitoring, not by customers.
Managed databases with point-in-time recovery, so a bad day stays a bad hour.
Credentials live in secret managers, never in code. Sensitive values are encrypted at rest and redacted from logs.
If you believe you've found a vulnerability in a XOLBY-operated property, email security@xolby.com with steps to reproduce. We acknowledge reports promptly, fix confirmed issues with urgency, and credit researchers who disclose responsibly.