How we protect your data.
Security is part of the product, not an annex. This page describes the infrastructure, controls, certifications and incident-response processes we apply by default to all clients.
// 01 · INFRASTRUCTURECloud-native, multi-region.
The entire X7 platform runs on cloud infrastructure with per-client isolation and multi-zone redundancy.
AWS · Vercel
Global edge functions. Cold-start < 100ms. Auto-scaling.
Supabase · Postgres
Postgres 15 with RLS (Row Level Security) by default. pgvector for embeddings.
EU + Middle East
Frankfurt (eu-central-1) and Bahrain (me-south-1). Locality per Client requirement.
Cloudflare · Vercel Edge
DDoS protection, WAF, bot mitigation, TLS termination at the edge.
// 02 · ENCRYPTIONBy default. No exceptions.
- In transit: TLS 1.3 mandatory. Certificates rotated automatically.
- At rest: AES-256 for all client data, including backups.
- Application: sensitive data (tokens, secrets) encrypted at application level before touching disk.
- Key management: AWS KMS with automatic rotation. Key access audited.
// 03 · AUTHENTICATION & ACCESSPrinciple of least privilege.
- SSO via Supabase Auth. Supports magic link, OAuth (Google, Microsoft), email/password with bcrypt password hashing.
- 2FA available. Recommended for all admin accounts.
- RLS in Postgres. Every query passes through security policies. Multi-tenancy guaranteed at database level.
- Credential rotation. API tokens with configurable expiration and immediate revocation.
- Audit logs. All administrative actions are logged and immutable.
// 04 · COMPLIANCECertifications and compliance.
SOC2 Type II
SOC2 Type II audit in progress. Preview report available under NDA. Final report expected Q4 2026. Covers Security, Availability, Confidentiality and Privacy principles.
LGPD (Brazil)
Designated DPO, RoPA, ANPD notification process.
GDPR (EU)
DPAs with sub-processors. SCCs for international transfer.
ISO 27001
Roadmap defined. Implementation start planned Q1 2027.
PDPL (Bahrain)
Law No. 30 of 2018. Data localized in Bahrain region when required.
// 05 · BACKUPS & DRTested recovery.
- Daily automatic backups. 30-day retention. Encrypted at rest.
- Point-in-time recovery (PITR). Recovery to any moment in the last 7 days.
- RTO (Recovery Time Objective): 4 hours.
- RPO (Recovery Point Objective): 24 hours (worst case), 1 hour (typical).
- Restoration tests: quarterly. Documented results.
// 06 · MONITORING24/7. Human alerts.
- Observability stack: Sentry (errors), Logflare (logs), Vercel Analytics, Supabase metrics.
- Public status page: under construction (status.x7growth.com).
- Critical alerts: notification to on-call engineer in < 5 minutes.
- SIEM: in implementation phase. Real-time security event correlation.
// 07 · INCIDENT RESPONSETransparency by default.
- Classification: incidents classified by severity (P0–P4) with specific playbooks.
- Client notification: within 72 hours for incidents affecting personal data (LGPD/GDPR).
- Public post-mortem: P0/P1 incidents trigger a public post-mortem within 14 days of resolution.
- Bug bounty: program in preparation. Responsible disclosure accepted via security@x7growth.com.
// 08 · SUB-PROCESSORSPublic list.
X7 uses carefully selected sub-processors, all with signed DPAs and their own certifications:
- AWS — Cloud infrastructure (SOC2, ISO 27001, GDPR)
- Vercel — Edge hosting & CDN (SOC2)
- Supabase — Database & Auth (SOC2 Type II)
- Stripe — Payments (PCI-DSS Level 1)
- Resend — Transactional email (SOC2)
- OpenAI / Anthropic — AI models (DPAs with training opt-out)
- Cloudflare — DNS, CDN, WAF (SOC2, ISO 27001)
Security information request?
For audits, RFPs, security questionnaires — contact directly.
security@x7growth.com