Every mechanism on this page is demonstrable live — bring your architects and your checklist to the demo.
The evidence lives in the tenant's own setup console — administrators diagnose jobs, imports, messages and access questions themselves, from the same governed experience as everything else.
In cloud data-centre regions in India. The production platform — application services, relational databases, the document store, file storage, caches and telemetry — runs in an Indian region, and backup storage is replicated to a second Indian region. Data residency for AI requests is covered on Sense trust & governance.
TLS 1.2 or higher is the enforced minimum on every connection — at the network edge and on every internal hop to the databases, document store, file storage and cache. At rest, every store is encrypted: relational databases under transparent data encryption, and the document store, file storage and backups under platform-managed encryption.
Secrets live in a managed vault, never in code or configuration files. Platform services authenticate to data stores and to each other with platform-managed workload identities rather than shared passwords — there is no standing credential to leak or rotate by hand.
Operational databases take automated, encrypted backups with point-in-time restore over a rolling window; configuration stores are backed up on a fixed cycle to geo-replicated storage within India. Formal recovery objectives (RPO/RTO) are documented in the business-continuity plan, available under NDA.
The application audit trail is tenant data: it records every data and configuration change with the acting identity, lives inside the tenant, and is retained for the life of the tenancy. Operational telemetry — service logs and metrics — is retained for 30 days.
In-app deletion passes through a recycle bin with a retention window, so deleted is not destroyed until the window lapses. On termination, tenant data is deleted in line with the Data Processing Addendum, and certification of deletion is available on request.
Both certifications are in progress. Until the reports are issued, the underlying documentation set — security policies, architecture descriptions and test summaries — is available under NDA; the table below lists each artifact and its status.
Yourselves, from the tenant's setup console: scheduled jobs carry their run history, imports keep per-run results, message logs show delivery per message, and request-level tracing is available for the tenant. The same console covers audit history and license usage — the operational evidence an evaluation asks for is the tenant administrator's to inspect, not ours to export.
Statuses are kept current. To request a document under NDA, write to sales@xmatix.com or ask your account contact.
| Document | Status |
|---|---|
| SOC 2 Type II report | In progress |
| ISO 27001 certificate | In progress |
| Penetration-test executive summary | Available under NDA |
| Vulnerability-management policy | Available under NDA |
| Incident-response policy | Available under NDA |
| Disaster-recovery & business-continuity plan, incl. RPO/RTO | Available under NDA |
| Data Processing Addendum | Published |
| Subprocessors list | Published |
| Privacy Policy | Published |
| Responsible AI statement | Published |