New: see the platform we built for NAV Productions: 7,500+ shoots and counting. Take the tour → sales@xolby.comsupport@xolby.com
Home / Security

Security is a build decision.

Every platform we ship carries the same security posture we run our own business on. Here's what that means in practice.

Our practices

The defaults every XOLBY build gets.

🔐

Encryption in transit

TLS everywhere, automatic certificate management, and HTTPS-only policies on every property we deploy.

🗝️

Least-privilege access

Role-based permissions, scoped API keys, and owner-only surfaces. People and services get the access they need and no more.

📜

Audit trails

Privileged actions are logged: who did what, to which record, from where. Accountability is a feature, not a forensics project.

🧯

Error telemetry

Production errors are captured, categorized, and surfaced to operators, so incidents get found by monitoring, not by customers.

💾

Backups & recovery

Managed databases with point-in-time recovery, so a bad day stays a bad hour.

🔏

Secrets hygiene

Credentials live in secret managers, never in code. Sensitive values are encrypted at rest and redacted from logs.

Responsible disclosure

Found something? Tell us first.

If you believe you've found a vulnerability in a XOLBY-operated property, email security@xolby.com with steps to reproduce. We acknowledge reports promptly, fix confirmed issues with urgency, and credit researchers who disclose responsibly.