1. Our approach to security
We use proportionate security measures based on data sensitivity, service risk and customer requirements. Security is considered in design, development, deployment and operation.
2. Baseline practices
- Access based on business need and least privilege.
- Strong authentication and multi-factor authentication where supported.
- Encryption in transit and appropriate encryption at rest via infrastructure providers.
- Dependency, configuration and vulnerability management.
- Logging, backup and recovery appropriate to the service.
- Vendor assessment and data-processing agreements where required.
3. Incident handling
Suspected security incidents are assessed, contained and documented. Where personal data is involved, notification duties are evaluated under applicable data-protection law and contractual commitments.
4. Responsible disclosure
To report a suspected vulnerability, email hello@zaxvix.com with “Security” in the subject. Include steps to reproduce, affected URLs or components and your contact details. Do not access data that is not yours, disrupt services or publish details before we have had a reasonable opportunity to investigate.