Security and compliance
Security and compliance
Data security and compliance for Xpancom clients.
A public view of the controls we operate, the privacy program we are building, and the certifications we have not claimed. Status chips are current program state, not issued certificates.
Program signals
- SOC 2In progress
- GDPRIn progress
- CCPA / CPRAIn progress
- ISO 27001 / 27018Target
- Penetration testingTarget
- HIPAAN/A
Statuses reflect current program state. Certificates and reports are available to qualified prospects under NDA when issued.
01 / Section
Examination status lives on the Trust Center.
SOC 2 examination status is published only on the Trust Center. That page is the single source of truth for whether a report exists. It currently reads: Security program in place.
This page does not display a certification badge. Program-signal chips under the hero map to Achieved, In progress, Target, or N/A. They are not a substitute for a CPA report.
02 / Section
SOC 2 program.
The hosted-system program is built against Security, Confidentiality, Availability. Security is required. Confidentiality matches the class of client information we hold. Availability matches the invitation-only workspace and managed operations.
Current state: Design Phase program; Type I/II not issued. We are in Design Phase: policies, public documents, and operating procedures are being seated as evidence. That is In progress, not Achieved.
Privacy as a Trust Services Category is optional for the first examination. The public Privacy Policy and Data Processing Addendum exist either way.
03 / Section
Privacy: GDPR, UK GDPR, and CCPA / CPRA.
GDPR and UK GDPR: privacy documents and the Data Processing Addendum are public. Live mailbox and data-subject-request verification is still pending, so the signal stays In progress.
CCPA / CPRA: California consumer rights are described on the Privacy Policy. Counsel review to deepen those disclosures is still open, so the signal stays In progress. We do not sell personal information and we do not share it for cross-context behavioral advertising.
Privacy questions go to privacy@xpancom.com. Use the request form on the Privacy Policy or email that mailbox. We respond within 45 days, or sooner where a shorter statutory period applies.
04 / Section
HIPAA is out of scope.
Protected health information is a Restricted class and is prohibited in Xpancom systems, including intake free text. The HIPAA chip is N/A, never Compliant, while that prohibition holds.
05 / Section
Encryption in transit and at rest.
Traffic to the public site, workspace, and auth is served over TLS by the host. Neon encrypts database data at rest. Application secrets live in the host environment, not in the repository. Intake URLs are credentials: only their hashes are stored.
Current evidence posture: hosted TLS is in production, and a dated configuration sample for reviewers is still being assembled. We describe the control that is in production. We do not publish a TLS screenshot as a certificate.
06 / Section
Application and edge protections.
Vercel hosts the marketing site, workspace, auth, and operator admin, and provides TLS and edge delivery. Neon hosts PostgreSQL. Twilio SendGrid sends transactional email. Twilio sends SMS one-time codes when SMS sign-in is enabled for an invited person.
We do not operate a separately named web application firewall product, and we do not invent a vendor brand for host-provided edge protections. Application access is invitation-only. There is no public signup. Operator admin adds an email allowlist and a time-based authenticator.
Those host and application controls are the honest stack. A procurement questionnaire should name Vercel, Neon, and Twilio rather than an unlisted WAF SKU.
07 / Section
Secure software development.
Production changes go through version control. Schema changes are applied with migrations, not by reseeding. Secrets are not committed. The marketing site does not load analytics or advertising scripts.
Current state: the pull-request path to the host is real. Required reviewers and automated dependency scanning are still being seated, so this signal stays In progress.
08 / Section
Audits and penetration testing.
Independent penetration testing is a Target. Scope is drafted and procurement is not authorized. There is no pentest letter on file to share under NDA yet.
ISO 27001 / 27018 is also a Target, intended after SOC 2 Type I footing. An ISMS engagement has not started. We will not display Achieved for a certificate that has not been issued.
09 / Section
Data protection contacts.
Use these mailboxes for privacy, security, and contracting. They are the public data-protection contacts for Xpancom, LLC. They are not a claim that a statutory data protection officer has been appointed in every jurisdiction.
- Privacy
- privacy@xpancom.com. Access, correction, deletion, export, restriction, and privacy notices.
- Security
- security@xpancom.com. Incidents, questionnaires, evidence, and vulnerability reports.
- Legal
- legal@xpancom.com. Contracts, the Data Processing Addendum, and counsel correspondence.
10 / Section
Subprocessors and cloud vendors.
Processors that handle personal data or client content on our behalf are listed on the subprocessors page. Today that register names Neon, Vercel, OpenAI, Twilio SendGrid, Twilio.
Vendor SOC 2 Type II packs for those processors are requested when a prospect needs them. They are not published as Xpancom certificates.
11 / Section
Data residency.
Default processing location is the United States. Neon and the application hosts listed as subprocessors currently run in the United States, with Vercel using a global edge network for delivery.
An EU residency option is a Target until the product offers a European Neon or Vercel region as a contracted choice. We will not advertise EU storage as available before that product decision.
12 / Section
Vulnerability disclosure.
Report a suspected issue to security@xpancom.com. The coordinated disclosure policy and security.txt describe scope, safe harbor, and what is out of bounds. There is no public bug bounty.
13 / Section
External trust score program.
Target external rating ≥ 97/100 (vendor TBD). No vendor is enrolled yet, and no current score is published. When a vendor is chosen and a score exists, this page will say so. Until then the goal is a Target, not a result.
14 / Section
Request current evidence.
Email security@xpancom.com from a company address. Name the engagement or prospect, and say whether you need the SOC 2 report, a security questionnaire, a certificate of insurance, or a pentest letter.
Those artifacts are not public downloads. If a report has not been issued, we will say so rather than share a placeholder PDF.