Trust Center · July 2026

Security & Trust

XFACTOR VERIFIED is a supply-chain security company. We hold ourselves to the standard we assess. This page states plainly what we do to protect your data, what we have verified, and what is still ahead. If it is written here, it is true today.

TLS 1.2+

Encryption in transit

Every connection is served over HTTPS. There is no unencrypted path to client data.

AES-256

Encryption at rest

Applied across database, file storage, and backups through our infrastructure providers.

13

Production audit layers

The full-stack audit we run on our own platform, from authentication to dependencies.

2 days

Disclosure acknowledgment

Business days to acknowledge any vulnerability report sent to our security inbox.

Data protection

All data is encrypted in transit and at rest. In transit, every connection is served over HTTPS with TLS 1.2 or higher. At rest, data is encrypted with AES-256 through our infrastructure providers.

One client's data is never visible to another. Tenant isolation is enforced at the database layer with row-level security, and every request is authenticated and scoped on our servers before any data is returned. The browser is never granted direct access to the database. Access follows least privilege: every person and every part of the system is granted only the access it needs.

How we audit ourselves

We run 13-layer production audits across the full stack: authentication, database, API surface, secrets, encryption, hosting, deployment, monitoring, scaling, recovery, data residency, incident response, and dependencies. The audit finds what needs fixing before anyone else can. Findings are fixed, fixes are re-verified, and the cycle repeats.

We do not hold SOC 2 or ISO 27001 certification today, and we will not imply otherwise. Formal attestation is on our roadmap. The controls those audits test are the ones described on this page, and they are in place now.

Vulnerability management

Every code change passes an automated secret-scanning gate before it can merge. Dependencies are audited for known vulnerabilities as part of our development cycle.

An internal red-team exercise was completed in July 2026. External penetration testing is planned. We will describe each exactly as it is: we do not label internal work as external, and we do not claim tests that have not happened.

Incident response

We maintain an incident response plan with defined severity levels and named responsibilities. If an incident affects your data, you hear it from us: what happened, what we did about it, and what happens next. Notification commitments are part of the plan, not a courtesy.

Data residency

Client application data is hosted in the United States. Primary database regions are US West (Oregon) and US East (N. Virginia), on Supabase infrastructure running on AWS, SOC 2 audited at the provider level, with data encrypted at rest and in transit in both regions. Canadian data residency is on our product roadmap.

Application hosting and content delivery run on Vercel's edge network.

Responsible disclosure

If you believe you have found a vulnerability in any XFACTOR system, report it to customercare@xfactorverified.com. We acknowledge every report within 2 business days and work with you on a coordinated disclosure timeline. Good-faith research is welcome here.

Subprocessors

We work with a small number of infrastructure providers. The core two:

ProviderPurpose
VercelApplication hosting and edge network
SupabaseDatabase, authentication, and file storage

The complete, current subprocessor list is available on request at customercare@xfactorverified.com.

For your security team

Send the questionnaire.

We answer security questionnaires directly and completely, and we would rather see yours before the contract than after. We will also walk your team through any control on this page.

Contact us

Last updated July 14, 2026 · XFACTOR COMMAND