TRUST CENTER

Security and Privacy at XELIA

How we protect your data, the technical controls already running in production, and the honest path to formal certifications. No fake badges. No claims we can't substantiate.

Compliance roadmap

XELIA operates today with controls designed to align with recognized frameworks. The distinction between "aligned" and "certified" matters, and we state it plainly: we are in progress, not at the finish line.

Implemented
GDPR (EU) and LFPDPPP (Mexico) compliance Operational data-handling controls, ARCO rights, retention, minimization, breach notification. Privacy Notice and DPA published publicly.
Implemented
Controls aligned with SOC 2 Type 2 (Trust Services Criteria) Availability, confidentiality, processing integrity, and privacy. Implemented as operational practice; not yet audited by an independent third party.
In progress
SOC 2 Type 1 Preparing the formal report with a certified auditor. Target ETA: Q4 2026
Planned
SOC 2 Type 2 + ISO/IEC 27001 Continuation of the certification program after SOC 2 Type 1. Roadmap: 2027

Technical controls in production

Each of the following controls is active today on production infrastructure and verified empirically on every deploy.

Multi-tenant isolation

Encryption

Authentication and authorization

Audit and observability

Input validation and webhook signing

Resilience and backups

Public documents

Detailed security whitepaper. Available on request to evaluating customers. Email security@xelia.ai with your organization; we typically respond within 24 business hours.

Incident and vulnerability reporting

If you discover a vulnerability or suspect an incident affecting XELIA or your data, contact us through the dedicated channel. We take every report seriously and respond within 24 business hours for security incidents.

We do not currently operate a paid bug-bounty program. We will publicly acknowledge responsible researchers (with their consent) on a thanks page when the formal program launches in 2027.

What we do not claim

XELIA is not certified in SOC 2 or ISO 27001 as of today. Certifications are 6–12 month processes with independent auditors; we are in preparation.

We do not display badges for certifications we do not hold. When we obtain each certification, we will publish on this same page the SOC 2 report (executive summary) or the ISO certificate with its number and validity dates.

Any commercial message or marketing piece claiming otherwise is an error — please report it to security@xelia.ai so we can correct it.