Security Policy
Effective Date: August 25, 2026 | Version 2.0Our Security Commitment
At Gixo.ai, we take the security of your data seriously. This policy outlines our comprehensive security practices and your role in maintaining a secure AI content generation environment.
Infrastructure Security
Data Centers
Hosted on Microsoft Azure cloud infrastructure
Microsoft holds SOC 2 Type II and ISO 27001 for the Azure facilities and platform services we run on. These are Microsoft's certifications, not Gixo's.
Geographically distributed for redundancy
Physical security controls are managed by our cloud infrastructure providers
Network Security
Web Application Firewall (WAF) protection
DDoS mitigation
Network monitoring and protective controls
Security monitoring and vulnerability management
Data Protection
Encryption:
| Type | Standard | Details |
|---|---|---|
| In Transit | TLS 1.3 | All communications encrypted |
| At Rest | AES-256 | All stored data encrypted |
| Key Management | Managed cloud key services | Provider-managed key storage and access controls |
| Database | TDE | Transparent data encryption enabled |
Access Controls:
Role-based access control (RBAC)
Principle of least privilege
Multi-factor authentication for admin access
Administrative access is limited to the founder. We do not yet run access reviews on a documented, evidenced cadence.
Application Security
Authentication
Secure email/password authentication
OAuth 2.0 integration
JWT tokens with short expiration
Secure refresh token rotation
Session Management
Secure session tokens
Automatic session timeout
CSRF protection
HttpOnly and Secure cookie flags
Development Security
Secure Development Lifecycle:
Security reviews in design phase
Compiler, analyzer, and automated test checks
Centrally managed dependency review
Focused review and release-gate verification
Engineering ownership and continuity
Gixo is founder-operated. Production changes use isolated source-control branches, relevant automated tests, Release builds, a curated deployment gate, one canonical deployment path, and post-deployment health verification. Read how engineering ownership works.
Third-Party Security:
Subprocessors are chosen for their own security posture and listed publicly on our Subprocessors page. We do not run a formal, documented vendor-assessment programme.
Automated dependency updates via Dependabot across .NET, npm, GitHub Actions and our container base image. Security updates are raised individually; routine updates batch weekly.
Dependency vulnerability alerts are enabled, and every push and pull request is scanned for committed secrets, with a full-history sweep weekly.
Minimal third-party integrations
Operational Security
Monitoring and Logging
Centralised application logging and a structured audit log covering sign-in, administrative action, export, share, checkout, policy change, data-lifecycle and agent-run events.
Logs are reviewed on investigation. We do not operate a SIEM or continuous human monitoring, and there is no 24/7 on-call rota.
Platform-level availability and failure alerting. We do not have automated behavioural alerting for suspicious account activity.
Audit records are retained for 365 days, then deleted automatically.
Incident Response
Security event monitoring and incident triage
Defined escalation procedures
Containment, remediation, and recovery workflows
Post-incident reviews and improvements
Compliance
We build to the requirements of the regimes below and will answer specific questions about any of them. This describes our operating posture — it is not a certification and not an audited finding of compliance:
What we do not have
If your review requires any of the following, we do not have it today. We would rather you knew before signing than after.
No SOC 2 Type I or Type II report, and no audit currently in progress.
No ISO 27001 certification of our own.
No recent third-party penetration test report.
No SAML federation or SCIM provisioning yet. Sign-in is OIDC-backed through our identity provider, including Google and Microsoft.
No data-residency choice. All data is held in a single Azure region.
No SIEM, no 24/7 security on-call. Gixo is founder-operated — plan for a bus factor of one.
User Security Responsibilities
Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities:
We commit to:
Review reported issues and triage them based on severity
Provide status updates when appropriate
Credit researchers (if desired) after resolution
Security Updates
Stay informed about security updates:
Email notifications for critical updates
In-app notifications for account-specific issues
Contact Information
Security Contact
Email: security@gixo.ai
Security inquiries and responsible disclosure reports are reviewed and triaged by Gixo's engineering owner
Company Address
Zencraft Consultancy Private Ltd.
A/10, Nootan Nagar, First Floor,
Bandra West,
Mumbai 400050
Maharashtra, India
This security policy is subject to change. Please check this page regularly for updates.
Last reviewed: July 2025 | © 2025 Zencraft Consultancy Private Ltd. All rights reserved.