Legal
Security Policy
How X2B AML Intel protects data and access, and how to report a vulnerability. This is a working draft.
Data protection
All API and app traffic is served over TLS. Sensitive assessment data stays inside authenticated accounts; public checks return redacted bands only and are not exposed publicly.
Access control
The analyst workspace is auth-gated in production with roles and an audit log, so access to findings is scoped and accountable. Protected actions require production authentication.
Vulnerability disclosure
Report suspected vulnerabilities to our security contact with enough detail to reproduce. Please give us reasonable time to remediate before any public disclosure, and do not access data that is not yours.
Incident handling
We investigate reported security incidents, take corrective action, and notify affected customers where required by law or contract. A formal incident-response runbook is being finalised.
Secrets and configuration
No secrets live in the frontend — only public build configuration. Backend credentials are held server-side and rotated per our internal procedures.
Ongoing hardening
Security is iterative. Formal policies, certifications, and a published disclosure program will be added as the platform matures; this page will track the current posture.
Report a vulnerability
Found a security issue? Email deals@x2b.io and we will follow up. For a non-legal overview of our practices, see the Security overview.