Trust Center

At XorFox, security and trust are foundational to everything we do. Drawbridge is built to protect your identity infrastructure with enterprise-grade security practices.

Security First

Security is built into every layer of our platform, from infrastructure to application code.

Data Encryption

All data is encrypted in transit using TLS 1.3 and at rest using AES-256 encryption.

Infrastructure

Hosted on enterprise-grade cloud infrastructure with redundancy and high availability.

Monitoring

24/7 monitoring and alerting to detect and respond to security events in real-time.

Security Practices

Access Control

We implement strict access control measures to ensure that only authorized personnel have access to customer data. Our access control practices include:

  • Role-based access control (RBAC) for all internal systems
  • Multi-factor authentication (MFA) required for all employees
  • Regular access reviews and principle of least privilege
  • Detailed audit logging of all administrative actions

Application Security

Drawbridge is built with security best practices throughout the development lifecycle:

  • Secure coding practices and regular code reviews
  • Static and dynamic application security testing (SAST/DAST)
  • Dependency vulnerability scanning
  • Regular penetration testing by third-party security firms

Data Protection

Your data is protected using industry-standard encryption and security measures:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Secure key management practices
  • Regular data backup with encrypted storage

Compliance

SOC 2 Type II

Drawbridge has completed a SOC 2 Type II audit, verifying our security, availability, and confidentiality controls over an extended observation period.

Incident Response

We maintain a comprehensive incident response plan to quickly identify, contain, and remediate security incidents. Our incident response process includes:

  • 24/7 security monitoring and alerting
  • Documented incident response procedures
  • Regular incident response drills and tabletop exercises
  • Timely notification to affected customers as required by law

Vendor Security

We carefully evaluate and monitor our third-party vendors to ensure they meet our security standards:

  • Security assessments before vendor onboarding
  • Contractual security and privacy requirements
  • Regular review of vendor security practices
  • Limited data sharing with vendors on a need-to-know basis

Contact Security Team

If you have questions about our security practices or need to report a security concern, please contact us:

We are committed to maintaining the highest security standards. If you discover a security vulnerability, please report it responsibly to security@xorfox.com.