Security
Security is part of the operating model.
Xemivo approaches security as a combination of architecture, access control, deployment discipline, monitoring and clear ownership.
Least privilege
Access should be limited to what each user, service or administrator needs to perform the intended function.
Secrets & credentials
Production credentials should not be embedded in source code or shared through public client-side assets.
Transport security
Production services should use HTTPS and modern TLS with secure DNS and certificate management.
Backups & recovery
Critical systems need backups appropriate to their data, recovery objectives and operational impact.
Monitoring
Infrastructure and application signals should make failures and suspicious activity visible enough to investigate.
Responsible reporting
Security concerns can be reported through Xemivo’s published contact channel and routed for review.