Security posture

The areas XPLG covers in its security program, one section each, for reviewers and auditors.

What you will do: find the section that matches a question in your security review, and know where to ask for the detail.

Each section below names the area and what XPLG documents for it. Detailed statements, evidence and current certifications are provided on request through a support ticket; see Getting help.

Security architecture and deployment trust model

Describes how the products are built and deployed, which components talk to which, and where the trust boundaries lie between your network, a self-managed deployment, XPLG SaaS and dock. Includes what data a registered deployment sends to dock and what stays on your side.

Authentication, SSO and identity

Covers how people and systems authenticate to dock and to the product consoles: password and provider sign-in, single sign-on with SAML and OIDC, two-factor authentication, API keys and the identities deployments use to report in.

Authorization, RBAC and permissions

Covers roles and permissions in dock (owner, admin, member, billing) and inside the products, how access is scoped to an organization, and how self-service stream management in PortX is bounded by administrator-set limits.

Data protection and encryption

Covers encryption of data in transit and at rest, the options to mask, encrypt and tokenize sensitive fields in motion, the checksummed archive, and key management. Details are under Data handling.

High availability, DR and continuity

Covers clustering, persistent queues that ride through destination outages, backup and restore of self-managed deployments, and the continuity arrangements for XPLG SaaS.

Infrastructure and operational security

Covers how XPLG operates its own infrastructure for dock and SaaS: hardening, access control, monitoring, vulnerability management, patching and incident response.

Secure SDLC and supply chain

Covers how the products are developed, reviewed, tested and released, how third-party components are tracked and updated, and how releases are signed and distributed.

Audit, compliance and governance

Covers the audit trails available in dock and the products, the frameworks XPLG aligns with, the policies that govern the security program and how customers can obtain evidence.

Certifications and attestations: <placeholder>

Next: Data handling

Verify with XPLG engineering before publishing.