Our approach
Xlines is a small, pre-launch company, and we'd rather describe our actual, current security practices honestly than list certifications we don't hold. This page will grow more detailed as the company and its infrastructure grow.
Measures in place today
- Encryption in transit: the Site is served over HTTPS/TLS.
- Form protection: contact and newsletter submissions are protected with WordPress nonce verification to guard against forged/cross-site requests.
- Restricted access: the website's admin panel and underlying database are accessible only to authorized Xlines personnel, using unique credentials.
- Minimal data collection: we collect only the fields needed to respond to an inquiry or run the newsletter — see our Privacy Policy.
- Backups: backup provider and cadence to be confirmed once hosting is finalized; this section will be updated with the specifics.
What we do not claim
We do not currently hold ISO 27001, SOC 2, PCI-DSS, or similar third-party security certifications. We are not implying otherwise anywhere on this site, and we will update this page — and only this page, honestly — if and when we obtain any such certification.
Incident response
If we become aware of a security incident affecting personal data, we will investigate promptly, take reasonable steps to contain and remediate it, and notify affected individuals and/or clients as required by applicable law and, for clients, our Data Processing Agreement.
What we're working toward
As Xlines grows, we intend to formalize written information-security policies, expand access controls and logging, and evaluate third-party security certification appropriate to our client base. We'd rather build this credibly over time than overstate our current maturity.
Reporting a concern
If you believe you've found a security vulnerability on this site, please report it responsibly to info@xlinescx.com rather than disclosing it publicly, and we'll respond as quickly as we can.