Sign In Try Free
Workflow-specific products Content, decks, briefs, proposals, legal, and sales each have a clearer buying path.
Review before delivery Draft, edit, collaborate, approve, and export in the same workspace.
Security + procurement path Security policy, support, and Azure Marketplace buying are public.

Security Policy

Effective Date: August 25, 2026 | Version 2.0
Our Security Commitment

At Gixo.ai, we take the security of your data seriously. This policy outlines our comprehensive security practices and your role in maintaining a secure AI content generation environment.

Infrastructure Security
Data Centers

Hosted on Microsoft Azure cloud infrastructure

Microsoft holds SOC 2 Type II and ISO 27001 for the Azure facilities and platform services we run on. These are Microsoft's certifications, not Gixo's.

Geographically distributed for redundancy

Physical security controls are managed by our cloud infrastructure providers

Network Security

Web Application Firewall (WAF) protection

DDoS mitigation

Network monitoring and protective controls

Security monitoring and vulnerability management

Data Protection
Encryption:
Type Standard Details
In Transit TLS 1.3 All communications encrypted
At Rest AES-256 All stored data encrypted
Key Management Managed cloud key services Provider-managed key storage and access controls
Database TDE Transparent data encryption enabled
Access Controls:

Role-based access control (RBAC)

Principle of least privilege

Multi-factor authentication for admin access

Administrative access is limited to the founder. We do not yet run access reviews on a documented, evidenced cadence.

Application Security

Authentication

Secure email/password authentication

OAuth 2.0 integration

JWT tokens with short expiration

Secure refresh token rotation

Session Management

Secure session tokens

Automatic session timeout

CSRF protection

HttpOnly and Secure cookie flags

Development Security
Secure Development Lifecycle:

Security reviews in design phase

Compiler, analyzer, and automated test checks

Centrally managed dependency review

Focused review and release-gate verification

Engineering ownership and continuity

Gixo is founder-operated. Production changes use isolated source-control branches, relevant automated tests, Release builds, a curated deployment gate, one canonical deployment path, and post-deployment health verification. Read how engineering ownership works.

Third-Party Security:

Subprocessors are chosen for their own security posture and listed publicly on our Subprocessors page. We do not run a formal, documented vendor-assessment programme.

Automated dependency updates via Dependabot across .NET, npm, GitHub Actions and our container base image. Security updates are raised individually; routine updates batch weekly.

Dependency vulnerability alerts are enabled, and every push and pull request is scanned for committed secrets, with a full-history sweep weekly.

Minimal third-party integrations

Operational Security
Monitoring and Logging

Centralised application logging and a structured audit log covering sign-in, administrative action, export, share, checkout, policy change, data-lifecycle and agent-run events.

Logs are reviewed on investigation. We do not operate a SIEM or continuous human monitoring, and there is no 24/7 on-call rota.

Platform-level availability and failure alerting. We do not have automated behavioural alerting for suspicious account activity.

Audit records are retained for 365 days, then deleted automatically.

Incident Response

Security event monitoring and incident triage

Defined escalation procedures

Containment, remediation, and recovery workflows

Post-incident reviews and improvements

Compliance

We build to the requirements of the regimes below and will answer specific questions about any of them. This describes our operating posture — it is not a certification and not an audited finding of compliance:

What we do not have

If your review requires any of the following, we do not have it today. We would rather you knew before signing than after.

No SOC 2 Type I or Type II report, and no audit currently in progress.

No ISO 27001 certification of our own.

No recent third-party penetration test report.

No SAML federation or SCIM provisioning yet. Sign-in is OIDC-backed through our identity provider, including Google and Microsoft.

No data-residency choice. All data is held in a single Azure region.

No SIEM, no 24/7 security on-call. Gixo is founder-operated — plan for a bus factor of one.

User Security Responsibilities
Account Security

Use strong, unique authentication methods

Use strong, unique passwords for your account

Don't share account credentials

Report suspicious activity immediately

API Security

Keep API keys confidential

Use environment variables for key storage

Rotate keys periodically

Implement rate limiting in your applications

Vulnerability Disclosure

We welcome responsible disclosure of security vulnerabilities:

We commit to:

Review reported issues and triage them based on severity

Provide status updates when appropriate

Credit researchers (if desired) after resolution

Security Updates

Stay informed about security updates:

Email notifications for critical updates

In-app notifications for account-specific issues

Contact Information

Security Contact

Email: security@gixo.ai
Security inquiries and responsible disclosure reports are reviewed and triaged by Gixo's engineering owner

Company Address

Zencraft Consultancy Private Ltd.
A/10, Nootan Nagar, First Floor,
Bandra West,
Mumbai 400050
Maharashtra, India


This security policy is subject to change. Please check this page regularly for updates.
Last reviewed: July 2025 | © 2025 Zencraft Consultancy Private Ltd. All rights reserved.