1. Security approach
We apply proportionate security measures based on data sensitivity, service risk and customer requirements. Security is considered throughout design, development, deployment and operation.
2. Core practices
- Access based on business need and least-privilege principles.
- Strong authentication and multi-factor authentication where supported.
- Encryption in transit and appropriate encryption at rest through infrastructure providers.
- Dependency, configuration and vulnerability management.
- Logging, backups and recovery practices appropriate to each service.
- Supplier assessment and written data-processing terms where required.
3. Incident handling
Suspected security incidents are assessed, contained and documented. Where personal data is involved, notification duties are evaluated under applicable data-protection law and contractual commitments.
4. Responsible disclosure
To report a suspected vulnerability, email hello@zaxvix.com with “Security” in the subject. Include steps to reproduce, affected URLs or components and your contact details. Do not access data that is not yours, disrupt services or publish details before we have had a reasonable opportunity to investigate.