Skip to content
Marketing in Motion
  • WorkWork
  • WebsitesWebsites
  • HostingHosting
  • AboutAbout
Discuss Your Business
Xpancom/Trust

Trust Center

Trust

How we hold client information, and how you can inspect that claim.

The Trust Center is the security designation for Xpancom: the hosted-system boundary, the Trust Services Criteria we operate against, the current examination status, and the documents procurement teams actually ask for.

Effective
15 September 2026
Updated
16 September 2026
Version
1.0
StatusSecurity program in place
CriteriaSecurity, Confidentiality, Availability
Last control review15 September 2026
On this page6 sections
  1. 01Current examination status
  2. 02What is in the hosted-system boundary
  3. 03Trust Services Criteria
  4. 04Control snapshots
  5. 05What we will not put on a client's system without authorization
  6. 06How to request a report

On this page

  1. 01Current examination status
  2. 02What is in the hosted-system boundary
  3. 03Trust Services Criteria
  4. 04Control snapshots
  5. 05What we will not put on a client's system without authorization
  6. 06How to request a report

01 / Section

Current examination status.

This page is the only place on the site that states SOC 2 examination status. We do not put a certification badge on the homepage, in the footer, or on About. When a report exists, qualified customers and prospects may request it under a non-disclosure agreement.

Security program in place

Controls, public documents, and operating procedures are in place. No SOC 2 report has been issued yet. Request current evidence and we will tell you what exists.

Trust Services Criteria
Security, Confidentiality, Availability
Last control review
15 September 2026
Evidence requests
security@xpancom.com
Request evidence at security@xpancom.comSecurity and complianceSecurity overview

02 / Section

What is in the hosted-system boundary.

In scope: the production cloud account that hosts xpancom.com, app.xpancom.com, auth.xpancom.com, and operator admin; the Neon database; transactional email and optional SMS; tokenized intake; and the invitation-only workspace.

Confidentiality procedures also cover discovery work on a client's own premises or tenant. That work is out of the hosted-system boundary for the first examination. Client-owned SaaS systems we are granted read-only access to remain the client's systems. Say It Live is a separate business and is out of scope.

03 / Section

Trust Services Criteria.

The program is built against Security, Confidentiality, Availability. Security is required. Confidentiality matches the class of client information we hold. Availability matches the invitation-only workspace and managed operations.

Processing integrity for AI workflows is an engagement control: models propose, named people approve, and exceptions are held. It is described in the AI Processing Terms. Privacy as a Trust Services Category is optional for the first examination; the public Privacy Policy exists either way.

AI Processing TermsPrivacy Policy

04 / Section

Control snapshots.

Access

Invitation-only grants. No public signup. Magic-link or SMS sign-in. Least privilege, named owners, and revocation that is actually tested.

Encryption

TLS in transit. Encryption at rest on Neon. Secrets in environment configuration, not in git.

Intake tokens

Only a SHA-256 hash of an intake token is stored. Reading the table cannot reconstruct a live URL.

Logging and backups

Operational logs, access reviews, and a rolling backup window with restore tests.

Vendors

Named subprocessors, written reviews, and notice before a material change.

People

Device and account standards, security training, and background checks appropriate to a small professional-services LLC.

05 / Section

What we will not put on a client's system without authorization.

Discovery starts read-only. We do not install unmanaged software, we do not take copies of regulated records into Xpancom systems, and we do not leave standing credentials behind. Production change rights, if they exist at all, are listed in the statement of work.

Professional Services Terms

06 / Section

How to request a report.

Email security@xpancom.com from a company address, name the engagement or prospect, and say whether you need the SOC 2 report, a security questionnaire, a certificate of insurance, or a pentest letter. Those artifacts are not public downloads. We will tell you what exists today.

Security and complianceSubprocessorsData retentionVulnerability disclosureData Processing AddendumLegal

Intro films, explainers, brand and product films, websites, and hosting from Xpancom.

High-impact motion for brands that need to sizzle.

Make

Intro filmsExplainersBrand & product filmsWebsitesHosting

Trust

Security and complianceTrust CenterSecuritySubprocessorsData retention

Company

WorkAll servicesAbout XpancomLegalDiscuss your business
© 2026 Xpancom, LLC. Marketing in Motion.
LegalPrivacyTermsCookiesAccessibilityServices termsDPA