Zaxvix
Legal center

Legal center

Security

How Zaxvix approaches the security of its website, systems and customer work.

Last updated: 26 July 2026

This page describes principles, not a certification or guarantee. Product-specific controls and contractual commitments will be documented separately as services mature.

1. Security approach

We apply proportionate security measures based on data sensitivity, service risk and customer requirements. Security is considered throughout design, development, deployment and operation.

2. Core practices

  • Access based on business need and least-privilege principles.
  • Strong authentication and multi-factor authentication where supported.
  • Encryption in transit and appropriate encryption at rest through infrastructure providers.
  • Dependency, configuration and vulnerability management.
  • Logging, backups and recovery practices appropriate to each service.
  • Supplier assessment and written data-processing terms where required.

3. Incident handling

Suspected security incidents are assessed, contained and documented. Where personal data is involved, notification duties are evaluated under applicable data-protection law and contractual commitments.

4. Responsible disclosure

To report a suspected vulnerability, email hello@zaxvix.com with “Security” in the subject. Include steps to reproduce, affected URLs or components and your contact details. Do not access data that is not yours, disrupt services or publish details before we have had a reasonable opportunity to investigate.

These documents are practical website policies and should be reviewed by qualified Swedish legal counsel before production use, especially when paid services, accounts, analytics or new processors are introduced.