Encryption
Xophia supports TLS 1.2 or higher in transit and AES-256 encryption at rest. Key ownership and any customer-managed-key requirement are confirmed during solution design.
Security controls are selected for each deployment scope, documented for review and improved as the assurance program matures.
Xophia supports TLS 1.2 or higher in transit and AES-256 encryption at rest. Key ownership and any customer-managed-key requirement are confirmed during solution design.
Resource-level role-based access control and SSO through SAML 2.0 or OIDC are available. Identity, service-account and privileged-access controls are documented for the selected deployment.
Logging, monitoring and incident-response responsibilities are defined for each deployment. Security notifications follow applicable law and the commitments in the customer agreement.
Independent testing is part of the assurance roadmap. The current testing scope, available evidence and remediation status are disclosed accurately during a security review.
Questions? Reach our team at legal@xophia.ai.