/ SECURITY
[ 06 / 06 ]

How we protect your data.

Security is part of the product, not an annex. This page describes the infrastructure, controls, certifications and incident-response processes we apply by default to all clients.

// Last updated · May 04, 2026

// 01 · INFRASTRUCTURECloud-native, multi-region.

The entire X7 platform runs on cloud infrastructure with per-client isolation and multi-zone redundancy.

// COMPUTE

AWS · Vercel

Global edge functions. Cold-start < 100ms. Auto-scaling.

// DATABASE

Supabase · Postgres

Postgres 15 with RLS (Row Level Security) by default. pgvector for embeddings.

// REGIONS

EU + Middle East

Frankfurt (eu-central-1) and Bahrain (me-south-1). Locality per Client requirement.

// CDN

Cloudflare · Vercel Edge

DDoS protection, WAF, bot mitigation, TLS termination at the edge.

// 02 · ENCRYPTIONBy default. No exceptions.

  • In transit: TLS 1.3 mandatory. Certificates rotated automatically.
  • At rest: AES-256 for all client data, including backups.
  • Application: sensitive data (tokens, secrets) encrypted at application level before touching disk.
  • Key management: AWS KMS with automatic rotation. Key access audited.

// 03 · AUTHENTICATION & ACCESSPrinciple of least privilege.

  • SSO via Supabase Auth. Supports magic link, OAuth (Google, Microsoft), email/password with bcrypt password hashing.
  • 2FA available. Recommended for all admin accounts.
  • RLS in Postgres. Every query passes through security policies. Multi-tenancy guaranteed at database level.
  • Credential rotation. API tokens with configurable expiration and immediate revocation.
  • Audit logs. All administrative actions are logged and immutable.

// 04 · COMPLIANCECertifications and compliance.

// IN PROGRESS

SOC2 Type II

SOC2 Type II audit in progress. Preview report available under NDA. Final report expected Q4 2026. Covers Security, Availability, Confidentiality and Privacy principles.

// COMPLIANT

LGPD (Brazil)

Designated DPO, RoPA, ANPD notification process.

// COMPLIANT

GDPR (EU)

DPAs with sub-processors. SCCs for international transfer.

// REVIEW

ISO 27001

Roadmap defined. Implementation start planned Q1 2027.

// COMPLIANT

PDPL (Bahrain)

Law No. 30 of 2018. Data localized in Bahrain region when required.

// 05 · BACKUPS & DRTested recovery.

  • Daily automatic backups. 30-day retention. Encrypted at rest.
  • Point-in-time recovery (PITR). Recovery to any moment in the last 7 days.
  • RTO (Recovery Time Objective): 4 hours.
  • RPO (Recovery Point Objective): 24 hours (worst case), 1 hour (typical).
  • Restoration tests: quarterly. Documented results.

// 06 · MONITORING24/7. Human alerts.

  • Observability stack: Sentry (errors), Logflare (logs), Vercel Analytics, Supabase metrics.
  • Public status page: under construction (status.x7growth.com).
  • Critical alerts: notification to on-call engineer in < 5 minutes.
  • SIEM: in implementation phase. Real-time security event correlation.

// 07 · INCIDENT RESPONSETransparency by default.

  • Classification: incidents classified by severity (P0–P4) with specific playbooks.
  • Client notification: within 72 hours for incidents affecting personal data (LGPD/GDPR).
  • Public post-mortem: P0/P1 incidents trigger a public post-mortem within 14 days of resolution.
  • Bug bounty: program in preparation. Responsible disclosure accepted via security@x7growth.com.

// 08 · SUB-PROCESSORSPublic list.

X7 uses carefully selected sub-processors, all with signed DPAs and their own certifications:

  • AWS Cloud infrastructure (SOC2, ISO 27001, GDPR)
  • Vercel Edge hosting & CDN (SOC2)
  • Supabase Database & Auth (SOC2 Type II)
  • Stripe Payments (PCI-DSS Level 1)
  • Resend Transactional email (SOC2)
  • OpenAI / Anthropic AI models (DPAs with training opt-out)
  • Cloudflare DNS, CDN, WAF (SOC2, ISO 27001)

Security information request?

For audits, RFPs, security questionnaires — contact directly.

security@x7growth.com
Security · X7 Growth AI | X7 Growth AI