Security & Privacy

Security & Privacy

Your data security and privacy are core platform concerns. XIntelliSync AI is built on partner-certified infrastructure with Australian-first privacy controls and globally aware security practices.

Enterprise Security
APP-Aware Privacy Controls
End-to-End Encryption

Security at a Glance

8
Security Domains
24/7
Security Monitoring
256-bit
AES Encryption
TLS 1.3
Transit Encryption

Security Features

End-to-End Encryption

All data encrypted in transit and at rest using industry-standard encryption

Implementation:

TLS 1.3 for data in transit, AES-256 encryption at rest via our certified database partner

Network Protection

DDoS protection, WAF, and global CDN delivered through our ISO 27001 and SOC 2 certified network protection partner

Implementation:

Partner-managed DDoS mitigation, Web Application Firewall, and SSL/TLS

Database Security

Row-Level Security, automated backups, and encryption powered by our SOC 2 Type II certified database partner

Implementation:

Partner-enforced RLS policies, AES-256 encryption, automated daily backups with point-in-time recovery

Role-Based Access Control

Granular permissions and access controls for team members with principle of least privilege

Implementation:

RBAC with multi-factor authentication, session management, and access logging

Security Assessments

Continuous automated security monitoring with regular vulnerability assessments

Implementation:

Automated vulnerability scanning, dependency auditing, and security monitoring

Privacy & Compliance

Privacy controls aligned with Australian Privacy Principles. Customers retain responsibility for their own APP and GDPR obligations.

Implementation:

Privacy by design, data minimisation, breach response preparation, and OAIC complaint-path support

Compliance & Certifications

Australian Privacy Act 1988

Platform incorporates controls aligned with the APPs. Customers are responsible for their own Privacy Act compliance obligations when processing personal information through the Platform.

Coverage: Customer Responsible

Aligned Controls

SOC 2 Type II Infrastructure

Built on SOC 2 Type II certified infrastructure partners

Coverage: Via Infrastructure Partners

Partner Certified

ISO 27001 Network Security

Network protection through our ISO 27001 certified network protection partner

Coverage: Via Network Partner

Partner Certified

PCI DSS Level 1 Payments

Payment processing through our PCI DSS Level 1 certified payments partner

Coverage: Via Payments Partner

Partner Certified

GDPR Awareness

Platform provides data subject request handling and consent-aware workflows. XIntelliSync does not represent GDPR compliance. Customers subject to GDPR retain their own compliance obligations.

Coverage: Customer Responsible

Awareness Only

ACSC Essential Eight

Security practices aligned with the Australian Cyber Security Centre Essential Eight framework

Coverage: Ongoing

Aligned

OWASP Top 10

Application security controls protecting against the OWASP Top 10 vulnerabilities

Coverage: Ongoing

Protected

NDB Scheme

Notifiable Data Breaches response procedures aligned to OAIC notification expectations

Coverage: Operational

Prepared

Data Protection Measures

Data Classification

All data is classified and handled according to sensitivity levels

Confidential
Internal
Public
Restricted

Access Logging

Comprehensive audit trails for all data access and modifications

User activity logs
API access logs
Admin action logs
System event logs

Data Backup

Automated backups with point-in-time recovery via our certified database partner

Daily automated backups
Point-in-time recovery
30-day retention
Encrypted backup storage

Incident Response

Defined incident response procedures with regulatory notification

Automated security monitoring
Incident response procedures
OAIC and customer notification where required by law
Post-incident analysis

Security Policies

Data Retention Policy

Clear guidelines on how long different types of data are retained

  • Customer data retained per subscription terms
  • Logs retained for 90 days for standard customers
  • Automated deletion of expired data
  • Data export available before deletion

Access Control Policy

Strict controls on who can access what data and systems

  • Multi-factor authentication supported
  • Role-based access with least privilege
  • Regular access reviews and deprovisioning
  • Privileged access monitoring

Incident Response Policy

Procedures for detecting, responding to, and recovering from security incidents

  • Automated security monitoring and alerting
  • Defined escalation procedures
  • OAIC and customer notification where required by law
  • Post-incident analysis and improvement

Vendor Security Policy

Security requirements for all third-party infrastructure partners

  • All infrastructure partners hold SOC 2 or ISO 27001 certifications
  • Contractual data processing agreements
  • Regular vendor security reviews
  • Australian Privacy Act compliance requirements

Threat Protection Matrix

Comprehensive protection against common security threats

DDoS Attacks

Protected

Partner DDoS Protection & WAF

SQL Injection

Protected

Parameterized queries + Row-Level Security

Cross-Site Scripting

Protected

Content Security Policy + Input validation

Brute Force Attacks

Protected

Rate limiting + Account lockout

Data Interception

Protected

TLS 1.3 encryption + partner-managed SSL

Unauthorised Access

Protected

RBAC + Row-Level Security + MFA

Enterprise Infrastructure Partners

Built on certified infrastructure from security partners

Database & Auth Partner
SOC 2 Type II

Database, Auth, RLS, Backups

Network & CDN Partner
ISO 27001 & SOC 2

CDN, DDoS, WAF, SSL/TLS

Payments Partner
PCI DSS Level 1

Payment Processing

Application Hosting Partner
SOC 2 Type II

Hosting Infrastructure

Security Questions?

Have security concerns or need to report a vulnerability? Our security team is here to help.

Security vulnerabilities: [email protected]

Security certifications referenced on this page (SOC 2 Type II, ISO 27001, PCI DSS Level 1) are held by the specialist infrastructure providers that underpin parts of our platform and cover the respective services they provide. XIntelliSync AI Pty Ltd implements security controls aligned with these frameworks and the ACSC Essential Eight, and maintains an Australian-first privacy program designed around the Privacy Act 1988 (Cth) and the Australian Privacy Principles.