Security
Effective: 2026-05-02
The controls below protect the platform and the data you send it. They are the same measures set out in Annex II of our data processing addendum, which we provide on request.
1. Encryption
- TLS 1.2 or later on everything in transit: ingestion, query endpoints, the portal, and service-to-service traffic inside the platform.
- AES-256 at rest for the primary database and for object storage.
2. Authentication and access
- API access uses bearer tokens, scoped per tenant and revocable from the portal at any time. See Authentication.
- Role-based access control in the portal: owner, admin, member.
- MFA is required on every operator account.
- Operators reach production through short-lived, just-in-time sessions. There are no long-lived production keys on operator workstations.
3. Tenant isolation
Customer data is isolated per tenant, at the metrics layer and again at the database layer. Access controls stop one tenant from reading another's data.
4. Network
Application workloads run in a private network with public ingress only at documented edge points.
5. Operations
- Administrative actions are written to an audit log, retained for 2 years.
- Backups run with point-in-time recovery on a 7-day window and inherit at-rest encryption.
- Managed services take vendor patches. Container images are rebuilt at least weekly onto current base images.
6. People
- Background checks for anyone with access to production data.
- Confidentiality agreements signed at onboarding.
- Security awareness training at onboarding and every year after.
7. Sub-processors
Every third party we engage is vetted before onboarding and bound by data-protection obligations. The current list is at xscalerlabs.com/sub-processors, and we give 30 days notice before it changes.
8. Incidents
If a personal data breach is likely to risk your rights, we notify the supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk is high.
9. Reporting a vulnerability
Email [email protected]. Please give us a chance to fix it before disclosing publicly. We will confirm receipt and keep you updated.
10. Contact
[email protected] for security questions, [email protected] for data protection questions.