Trust Center
Trust
How we hold client information, and how you can inspect that claim.
The Trust Center is the security designation for Xpancom: the hosted-system boundary, the Trust Services Criteria we operate against, the current examination status, and the documents procurement teams actually ask for.
01 / Section
Current examination status.
This page is the only place on the site that states SOC 2 examination status. We do not put a certification badge on the homepage, in the footer, or on About. When a report exists, qualified customers and prospects may request it under a non-disclosure agreement.
02 / Section
What is in the hosted-system boundary.
In scope: the production cloud account that hosts xpancom.com, app.xpancom.com, auth.xpancom.com, and operator admin; the Neon database; transactional email and optional SMS; tokenized intake; and the invitation-only workspace.
Confidentiality procedures also cover discovery work on a client's own premises or tenant. That work is out of the hosted-system boundary for the first examination. Client-owned SaaS systems we are granted read-only access to remain the client's systems. Say It Live is a separate business and is out of scope.
03 / Section
Trust Services Criteria.
The program is built against Security, Confidentiality, Availability. Security is required. Confidentiality matches the class of client information we hold. Availability matches the invitation-only workspace and managed operations.
Processing integrity for AI workflows is an engagement control: models propose, named people approve, and exceptions are held. It is described in the AI Processing Terms. Privacy as a Trust Services Category is optional for the first examination; the public Privacy Policy exists either way.
04 / Section
Control snapshots.
Access
Invitation-only grants. No public signup. Magic-link or SMS sign-in. Least privilege, named owners, and revocation that is actually tested.
Encryption
TLS in transit. Encryption at rest on Neon. Secrets in environment configuration, not in git.
Intake tokens
Only a SHA-256 hash of an intake token is stored. Reading the table cannot reconstruct a live URL.
Logging and backups
Operational logs, access reviews, and a rolling backup window with restore tests.
Vendors
Named subprocessors, written reviews, and notice before a material change.
People
Device and account standards, security training, and background checks appropriate to a small professional-services LLC.
05 / Section
What we will not put on a client's system without authorization.
Discovery starts read-only. We do not install unmanaged software, we do not take copies of regulated records into Xpancom systems, and we do not leave standing credentials behind. Production change rights, if they exist at all, are listed in the statement of work.
06 / Section
How to request a report.
Email security@xpancom.com from a company address, name the engagement or prospect, and say whether you need the SOC 2 report, a security questionnaire, a certificate of insurance, or a pentest letter. Those artifacts are not public downloads. We will tell you what exists today.