Trust Center
The claims on this page are specific because they are checkable. Evidence for each is held in our compliance corpus; request it from the security contact below.
Tenant isolation
Every realm gets its own database schema. Separation is enforced at the storage layer, not by row filters in a shared table.
- Tenant-admin roles are scoped to their own realm; cross-tenant endpoints are restricted to XorFox operators
- Secrets live in a separate vault store with envelope encryption (AES-256-GCM)
Encryption
TLS for all traffic. AES-256 at rest on RDS and S3.
Infrastructure
AWS. Multi-AZ PostgreSQL with daily backups and 30-day retention. Three-node Docker Swarm in a private VPC. Restore procedure tested.
Supply chain
Release images are signed and verified before deploy; deploys fail closed. Registry scans on every push.
Monitoring
Every service emits telemetry to a central monitor with alerting. The incident response plan was last exercised 2026-08-23.
Security Practices
Access Control
We implement strict access control measures to ensure that only authorized personnel have access to customer data. Our access control practices include:
- Role-based access control (RBAC) for all internal systems
- Multi-factor authentication (MFA) required for all employees
- Regular access reviews and principle of least privilege
- Detailed audit logging of all administrative actions
Application Security
Drawbridge is built with security best practices throughout the development lifecycle:
- Cosign-signed release images, verified before deploy; deploys fail closed
- Trivy vulnerability scans of the container registry
- Enforced review on the main branch; no direct pushes
- Web application firewall enforced at the edge
Data Protection
Your data is protected using industry-standard encryption and security measures:
- TLS for all data in transit
- AES-256 encryption for data at rest on RDS and S3
- Secure key management practices
- Daily backups with 30-day retention in encrypted storage
Agent control
Agents are first-class identities with bounded authority. The platform enforces the bounds on every tool call, not on an honor system:
- Every agent authenticates with its own Keycloak client credential; it never holds the owner's password or token, and its access tokens expire in 5 minutes
- Authority comes only from an explicit delegation: capability scopes drawn from a fixed 22-scope vocabulary, with an expiry capped at 90 days
- Every MCP tool call is re-checked server side and fails closed: unregistered, revoked, expired, or out-of-scope calls are denied before execution
- Revocation takes effect on the agent's next call. Rotated credentials invalidate the old secret immediately; tokens already issued age out within 5 minutes
- Denials are always audited. Security events are stored append-only (updates and deletes are rejected by the database) and hash-chained, so tampering is detectable
- Agents are rate-limited to 60 calls per minute and capped at 10 per account
Compliance
SOC 2 Type II
Drawbridge is SOC 2 Type II certified. The audit examined controls over an extended observation period, not a point-in-time snapshot. Request the report: security@xorfox.com.
Incident Response
We maintain a documented incident response plan to identify, contain, and remediate security incidents. Our incident response process includes:
- Centralized telemetry and alerting across every service
- Documented incident response procedures
- Regular exercises; the plan was last tested 2026-08-23
- Timely notification to affected customers as required by law
Vendor Security
We carefully evaluate and monitor our third-party vendors to ensure they meet our security standards:
- Security assessments before vendor onboarding
- Contractual security and privacy requirements
- Regular review of vendor security practices
- Limited data sharing with vendors on a need-to-know basis
Contact Security Team
If you have questions about our security practices or need to report a security concern, please contact us:
- Security Email: security@xorfox.com
- General Inquiries: support@xorfox.com
If you discover a security vulnerability, please report it responsibly to the security email above.