Security posture
The areas XPLG covers in its security program, one section each, for reviewers and auditors.
What you will do: find the section that matches a question in your security review, and know where to ask for the detail.
Each section below names the area and what XPLG documents for it. Detailed statements, evidence and current certifications are provided on request through a support ticket; see Getting help.
Security architecture and deployment trust model
Describes how the products are built and deployed, which components talk to which, and where the trust boundaries lie between your network, a self-managed deployment, XPLG SaaS and dock. Includes what data a registered deployment sends to dock and what stays on your side.
Authentication, SSO and identity
Covers how people and systems authenticate to dock and to the product consoles: password and provider sign-in, single sign-on with SAML and OIDC, two-factor authentication, API keys and the identities deployments use to report in.
Authorization, RBAC and permissions
Covers roles and permissions in dock (owner, admin, member, billing) and inside the products, how access is scoped to an organization, and how self-service stream management in PortX is bounded by administrator-set limits.
Data protection and encryption
Covers encryption of data in transit and at rest, the options to mask, encrypt and tokenize sensitive fields in motion, the checksummed archive, and key management. Details are under Data handling.
High availability, DR and continuity
Covers clustering, persistent queues that ride through destination outages, backup and restore of self-managed deployments, and the continuity arrangements for XPLG SaaS.
Infrastructure and operational security
Covers how XPLG operates its own infrastructure for dock and SaaS: hardening, access control, monitoring, vulnerability management, patching and incident response.
Secure SDLC and supply chain
Covers how the products are developed, reviewed, tested and released, how third-party components are tracked and updated, and how releases are signed and distributed.
Audit, compliance and governance
Covers the audit trails available in dock and the products, the frameworks XPLG aligns with, the policies that govern the security program and how customers can obtain evidence.
Certifications and attestations: <placeholder>
Next: Data handling
Verify with XPLG engineering before publishing.