Security & Compliance

XnoleX is built with a security-first architecture. We apply the same rigor to our own platform that we help you apply to yours.

Security Controls

RSA256 JWT Authentication

Asymmetric key-based token signing with RS256 algorithm. Private keys stored with filesystem permissions (chmod 400).

Role-Based Access Control

Granular RBAC with Owner, Admin, Manager, Operator, and Viewer roles. Permission-gated endpoints.

Secrets Encryption

AES-256-GCM encryption for stored secrets and API keys. Fernet symmetric encryption for at-rest data.

Audit Logging

Immutable audit log recording all API calls with user, action, resource, timestamp, and success/failure status.

Rate Limiting

Per-user and per-endpoint rate limits with configurable thresholds. Login brute-force protection.

Network Security

TLS 1.2+ encryption in transit. HTTP security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options).

Compliance Alignment

While XnoleX is not formally certified, our security architecture is aligned with industry standards including OWASP Top 10, SOC 2 Type II controls, and GDPR data protection requirements.

OWASP Top 10
SOC 2 Aligned
GDPR Ready
Encryption at Rest

Reporting Security Issues

If you discover a security vulnerability in XnoleX, please report it responsibly by contacting our security team at security@xnolex.com. We take all reports seriously and will respond within 48 hours.