HomeAbout
BlogContact
Start a project
Trust & Safety

Security at XTRE

Security is not a feature — it's a foundation. Every project we deliver is built with defence-in-depth from day one.

Encryption everywhere

All data in transit is encrypted with TLS 1.3. Data at rest uses AES-256. Encryption keys are rotated quarterly and stored in a dedicated key management service.

Access control

Role-based access control (RBAC) limits data access to authorised personnel only. Multi-factor authentication (MFA) is mandatory for all internal systems and client environments.

Infrastructure security

Client infrastructure is deployed in ISO 27001-certified cloud environments (AWS, Azure, GCP). Network segmentation, WAF protection, and regular vulnerability scans are standard.

Code review & SAST

All production code undergoes peer review and automated static analysis (SAST) scanning before deployment. We follow OWASP Top 10 guidelines as a baseline for every project.

Incident response

We maintain a documented incident response plan with defined escalation paths. In the event of a breach affecting client data, we notify within 72 hours as required by applicable law.

Backup & recovery

Automated daily backups with point-in-time recovery. Backups are tested monthly. RTO and RPO targets are documented in each client's SLA and verified during quarterly drills.

Report a vulnerability

If you discover a security issue in any of our systems or client projects managed by XTRE, please disclose it responsibly. We commit to acknowledging reports within 24 hours and resolving confirmed issues within 30 days.

security@xtre.io
← Back to home