Security Overview
XIntelliSync AI Pty Ltd
Document Version 2.0 — Effective 1 March 2026
This Security Overview describes the data protection measures, security controls, and compliance posture maintained by XIntelliSync AI Pty Ltd ("XIntelliSync", "we", "us", "our") in the operation of the XIntelliSync AI Business Operating System (the "Platform").
This document is provided for informational purposes to current and prospective customers, their legal advisors, and compliance teams. It does not constitute a warranty, guarantee, or certification. The security posture described herein reflects the Platform's controls as at the date of this document and is subject to ongoing improvement.
For questions regarding this document or to request further detail under mutual non-disclosure agreement, contact [email protected].
Scope of This Document
This Security Overview covers the following aspects of the Platform:
Data encryption controls (in transit and at rest)
Authentication and access control mechanisms
Database security and tenant data isolation
Third-party infrastructure partner certifications
Compliance posture and regulatory alignment
AI data handling and privacy commitments
Incident detection and response procedures
Data retention and deletion practices
This document does not cover customer-side security configurations, end-user device security, or the security of third-party integrations connected by customers to their accounts.
Data Encryption
All customer data is encrypted both in transit and at rest:
In Transit: All communication between clients and the Platform is encrypted using TLS 1.3. HTTP Strict Transport Security (HSTS) headers are enforced across all endpoints. No unencrypted connections are accepted.
At Rest: All customer data is encrypted using AES-256 encryption at the infrastructure level. Encryption key management is handled by our certified infrastructure partners and keys are not accessible to application code. Backup data is similarly encrypted.
Payment Data: Payment card data is processed and stored exclusively by our PCI DSS Level 1 certified payment processor. XIntelliSync does not receive, process, or store payment card numbers at any point in the transaction lifecycle.
Authentication and Access Control
User Authentication: The Platform employs industry-standard authentication with secure password hashing. Multi-factor authentication (MFA) is available for all user accounts.
Session Management: Token-based session management with configurable expiry. Sessions are invalidated on password change or explicit logout.
Role-Based Access Control: A tiered access model ensures users can only access features and data permitted by their subscription level and organisational role. Administrative functions are restricted to authorised personnel with elevated privileges.
Brute-Force Protection: Rate limiting is applied to authentication endpoints to prevent credential-stuffing and brute-force attacks. The system is designed to avoid cross-user lockouts on shared network environments.
Database Security and Tenant Isolation
Row-Level Security: All customer data tables enforce Row-Level Security (RLS) policies at the database level. Every query against customer data is scoped to the authenticated user's account. Cross-tenant data access is technically isolated through Row-Level Security policies enforced at the database level.
Query Isolation: All database interactions are executed through a controlled data access layer that enforces parameterised queries and mandatory user-context filtering. Direct unscoped queries are prohibited by design.
Data Segregation: Customer business data, system operational data, and AI processing data are stored in separate, isolated data stores with distinct access credentials. This segregation limits the impact of any single-point compromise.
Application Security
Input Validation: All user inputs are validated and sanitised at the API boundary. Content Security Policy (CSP) headers are enforced to mitigate cross-site scripting (XSS) attacks.
SQL Injection Prevention: Parameterised queries are used for all database interactions, eliminating SQL injection vectors.
OWASP Top 10: Application security controls are designed to address the Open Web Application Security Project (OWASP) Top 10 vulnerabilities, including injection, broken authentication, sensitive data exposure, and security misconfiguration.
Dependency Management: Application dependencies are regularly audited for known vulnerabilities. Security patches are applied as part of the continuous deployment pipeline.
Secret Management: All secrets, API keys, and credentials are stored in secure environment variables. No secrets are committed to source code or logged in application output.
AI Data Handling
Processing Scope: Customer business data processed by AI features is used solely for generating the requested output (e.g., analysis, categorisation, report generation). Data is processed on-demand and only for the specific task initiated by the user.
Data Retention by Providers: AI inference providers used by the Platform do not retain customer data beyond the scope of the individual request, in accordance with each provider's data processing terms.
No Training on Customer Data: Customer data is not used to train, fine-tune, or improve any AI models. All AI processing is stateless with respect to customer data.
Transparency: AI-generated outputs are clearly identified as such within the Platform. Users maintain full control over which data is submitted for AI processing.
Infrastructure Partner Certifications
XIntelliSync builds on certified infrastructure from trusted partners. The certifications listed below are held by the respective infrastructure providers and cover the services they provide to XIntelliSync:
SOC 2 Type II: Our primary database provider and application hosting provider each hold SOC 2 Type II attestations, covering availability, security, and confidentiality controls.
ISO 27001 and SOC 2: Our network protection and CDN provider holds ISO 27001 and SOC 2 certifications, covering DDoS mitigation, Web Application Firewall (WAF), and SSL/TLS management.
PCI DSS Level 1: Our payment processing partner holds PCI DSS Level 1 certification — the highest level of payment card industry compliance.
XIntelliSync AI Pty Ltd does not independently hold SOC 2, ISO 27001, or PCI DSS certifications. Copies of partner attestation reports may be available upon request under mutual non-disclosure agreement, subject to the respective provider's sharing policies.
Regulatory Alignment
Privacy Act 1988 (Cth): XIntelliSync incorporates controls aligned with the Australian Privacy Principles (APPs). Data collection is limited to what is reasonably necessary for platform operation. Users may request access to, correction of, or deletion of their personal information. Customers remain responsible for their own APP compliance obligations in connection with the personal information they process through the Platform.
Notifiable Data Breaches (NDB) Scheme: XIntelliSync maintains documented incident response procedures. In the event of an eligible data breach, notification will be provided to the Office of the Australian Information Commissioner (OAIC) and affected individuals in accordance with Part IIIC of the Privacy Act 1988.
ACSC Essential Eight: Security practices are aligned with the Australian Cyber Security Centre Essential Eight mitigation strategies, including application patching, restriction of administrative privileges, and multi-factor authentication.
GDPR Awareness: XIntelliSync is not established in the European Union and does not represent that the Platform is GDPR-compliant. For users in jurisdictions subject to the General Data Protection Regulation, the Platform provides data subject request handling and consent-aware workflows where applicable. Customers subject to GDPR obligations are responsible for their own compliance, including any data processing agreements required under Article 28.
Government Lodgement: XIntelliSync is not an ATO Digital Service Provider. Tax and regulatory features operate on a prepare-download-instruct model: the Platform prepares documents (e.g., BAS, STP) for download, and the user lodges externally through the relevant government portal.
Incident Response
Detection: Automated security monitoring through infrastructure-level WAF, database audit logs, and application-level error tracking. Anomalous access patterns trigger automated alerts.
Response: Defined escalation procedures with documented roles and responsibilities. Critical security incidents are triaged as soon as reasonably practicable following detection.
Notification: Where a data breach meets the threshold for notification under the NDB Scheme, the OAIC and affected individuals will be notified as soon as practicable, and no later than 30 days after the entity becomes aware of reasonable grounds to believe an eligible data breach has occurred.
Post-Incident: All security incidents are followed by a post-incident review to identify root causes and implement preventive measures.
Data Retention and Deletion
Customer business data is retained for the duration of the active subscription. Upon subscription cancellation, account data is retained for 30 days to allow for reactivation, after which it is scheduled for permanent deletion.
Application and access logs are retained for 90 days for standard customers. Enterprise customers may request extended retention under their service agreement.
Customers may request a complete data export at any time via the Platform's export functionality or by contacting [email protected].
Deletion requests are processed in accordance with the Australian Privacy Principles and, where applicable, GDPR data subject rights.
Contact and Further Information
For security inquiries, vulnerability reports, or to request additional security documentation under non-disclosure agreement:
Security Team: [email protected]
Privacy Officer: [email protected]
General Support: [email protected]
XIntelliSync AI Pty Ltd reserves the right to update this Security Overview from time to time. Material changes will be communicated to active subscribers via email notification. The current version of this document is always available at xintellisync.com/security-overview.
© 2026 XIntelliSync AI Pty Ltd. All rights reserved. This document is confidential and intended for the use of the addressee only. Unauthorised distribution or reproduction is prohibited.