Legal
Security
1. Our practices
- Encryption in transit and at rest for all customer data.
- Least-privilege access, with production access logged and reviewed monthly.
- Independent penetration testing twice a year, summarised in our trust report.
- Hosted agents execute in a sandbox with no ambient credentials.
2. Reporting a vulnerability
Write to security@xmad.ai with a description and, if possible, a minimal reproduction. We acknowledge within 24 hours and aim to resolve confirmed issues within 90 days.
3. Safe harbour
We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service degradation, and give us reasonable time to fix an issue before publishing.
4. Incident disclosure
Confirmed incidents affecting customer data are disclosed to affected accounts within 72 hours, and summarised publicly in our incident log.