Security at xonPlus
We know security matters, and we've built our product with that in mind from day one.
Our SaaS platform runs on a serverless setup using trusted names like Cloudflare and Google Cloud. That means fewer moving parts, fewer risks, and less that can go wrong for you.
Hardened Infrastructure
Cloudflare WAF in front, Google Cloud Run behind, no servers of our own to patch
Encrypted in Transit and at Rest
TLS 1.3 on every connection, AES-256 for stored data and backups
Supports Your Compliance
Published DPA with SCCs, sub-processor list, and audit-ready alert logs
Built on Trusted Infrastructure
Cloudflare Pages for the Web App
Our frontend is hosted on Cloudflare Pages, giving you fast, secure access through their global CDN. SSL, DDoS protection, and smart filtering are all part of the package.
Google Cloud Run for the API
Our backend runs on Google Cloud Run, backed by Google's infrastructure and security standards.
Built on Certified Infrastructure
Google Cloud is certified with SOC 2, ISO 27001, and more. Your data is protected with the same standards trusted by the world's top companies.
No Servers to Patch
Serverless by Design
We don't run any traditional servers. This architectural choice eliminates entire categories of security risks and maintenance overhead.
Secured by Design
Web Protection with Cloudflare WAF
All web traffic is filtered through Cloudflare's Web Application Firewall to block threats before they even reach us.
Regular Security Testing
Our app and API are regularly tested by security professionals. If something needs fixing, we fix it fast.
Strict API Rate Limiting
We enforce rate limits on every API route. That keeps things fair, stable, and safe from abuse.
Monitoring and Logging
Centralised Logging
We log system performance, security events, and administrative actions centrally in Google Cloud, with automated alerting on critical events. Logs are encrypted and access-controlled.
Secure Storage
All logs stored in Google Cloud, encrypted at rest with AES-256
Performance Monitoring
Real-time tracking of system performance and response times
Anomaly Detection
Automated detection of unusual activity patterns and potential threats
Security Practices
Encryption
AES-256 at rest, TLS 1.3 in transit
Backups
Regular encrypted backups with 30-day retention
Audits
Periodic third-party penetration testing
Incident Response
Breach notification within 72 hours, per our DPA
Security Contact
Report security vulnerabilities or concerns
We acknowledge vulnerability reports within 1 business day. We will not pursue legal action against good-faith security research that respects user privacy and avoids service disruption. Machine-readable details: security.txt
Security You Can Rely On
Built for Trust
We've designed our platform to be secure from the ground up. With modern infrastructure, smart protections, and regular testing, your data is in good hands.