Trust Center

The claims on this page are specific because they are checkable. Evidence for each is held in our compliance corpus; request it from the security contact below.

Tenant isolation

Every realm gets its own database schema. Separation is enforced at the storage layer, not by row filters in a shared table.

  • Tenant-admin roles are scoped to their own realm; cross-tenant endpoints are restricted to XorFox operators
  • Secrets live in a separate vault store with envelope encryption (AES-256-GCM)

Encryption

TLS for all traffic. AES-256 at rest on RDS and S3.

Infrastructure

AWS. Multi-AZ PostgreSQL with daily backups and 30-day retention. Three-node Docker Swarm in a private VPC. Restore procedure tested.

Supply chain

Release images are signed and verified before deploy; deploys fail closed. Registry scans on every push.

Monitoring

Every service emits telemetry to a central monitor with alerting. The incident response plan was last exercised 2026-08-23.

Security Practices

Access Control

We implement strict access control measures to ensure that only authorized personnel have access to customer data. Our access control practices include:

  • Role-based access control (RBAC) for all internal systems
  • Multi-factor authentication (MFA) required for all employees
  • Regular access reviews and principle of least privilege
  • Detailed audit logging of all administrative actions

Application Security

Drawbridge is built with security best practices throughout the development lifecycle:

  • Cosign-signed release images, verified before deploy; deploys fail closed
  • Trivy vulnerability scans of the container registry
  • Enforced review on the main branch; no direct pushes
  • Web application firewall enforced at the edge

Data Protection

Your data is protected using industry-standard encryption and security measures:

  • TLS for all data in transit
  • AES-256 encryption for data at rest on RDS and S3
  • Secure key management practices
  • Daily backups with 30-day retention in encrypted storage

Agent control

Agents are first-class identities with bounded authority. The platform enforces the bounds on every tool call, not on an honor system:

  • Every agent authenticates with its own Keycloak client credential; it never holds the owner's password or token, and its access tokens expire in 5 minutes
  • Authority comes only from an explicit delegation: capability scopes drawn from a fixed 22-scope vocabulary, with an expiry capped at 90 days
  • Every MCP tool call is re-checked server side and fails closed: unregistered, revoked, expired, or out-of-scope calls are denied before execution
  • Revocation takes effect on the agent's next call. Rotated credentials invalidate the old secret immediately; tokens already issued age out within 5 minutes
  • Denials are always audited. Security events are stored append-only (updates and deletes are rejected by the database) and hash-chained, so tampering is detectable
  • Agents are rate-limited to 60 calls per minute and capped at 10 per account

Compliance

SOC 2 Type II

Drawbridge is SOC 2 Type II certified. The audit examined controls over an extended observation period, not a point-in-time snapshot. Request the report: security@xorfox.com.

Incident Response

We maintain a documented incident response plan to identify, contain, and remediate security incidents. Our incident response process includes:

  • Centralized telemetry and alerting across every service
  • Documented incident response procedures
  • Regular exercises; the plan was last tested 2026-08-23
  • Timely notification to affected customers as required by law

Vendor Security

We carefully evaluate and monitor our third-party vendors to ensure they meet our security standards:

  • Security assessments before vendor onboarding
  • Contractual security and privacy requirements
  • Regular review of vendor security practices
  • Limited data sharing with vendors on a need-to-know basis

Contact Security Team

If you have questions about our security practices or need to report a security concern, please contact us:

If you discover a security vulnerability, please report it responsibly to the security email above.