Back to home

Security

How the platform protects data, and what we do and do not claim.

Effective date: 13 August 2026

For the contractual version of these commitments see our Data Processing Addendum.

1. Hosting and data residency

The platform is cloud-hosted on infrastructure operated within the European Union. Customers who require their own deployment can host the platform on their own servers under a separate written agreement; in that case data never leaves their infrastructure.

Production, staging and development environments are separated. Production credentials are not available in non-production environments.

2. Encryption

All traffic between your browser and the platform is encrypted in transit using TLS.

Stored data is encrypted at rest.

API credentials and secrets are held server-side only. They are never embedded in client applications and are not visible to customers.

3. Access control

Row-level authorisation is enforced in the database, so one customer's records cannot be read by another.

Administrative access is individually named, least-privilege and logged.

Access to customer data for support purposes is limited to the scope and duration of the support request and is recorded.

4. Backups and continuity

Data is backed up regularly and restoration is tested. Customers can export their own data at any time from the platform in a machine-readable format, and may request an export at the end of their subscription term.

5. Human approval on binding actions

The platform generates recommendations and drafts. Nothing that creates a legal or commercial obligation — a quotation, a proforma invoice, a customs declaration, a signed document — leaves the system without the customer's explicit approval. This is a deliberate design constraint, not a configuration option.

6. AI processing

Content submitted to AI models for generation or analysis is sent to the model providers listed on our Subprocessors page. We do not use customer content to train third-party foundation models.

Product improvement relies on aggregate, non-identifying usage statistics only.

7. Vulnerability reporting

If you believe you have found a security vulnerability, write to info@eximlabs.ai with the subject line "Security". Please give us a reasonable period to investigate and remediate before any public disclosure. We do not pursue legal action against researchers who report in good faith and do not access or modify data beyond what is necessary to demonstrate the issue.

8. Incident response

If a personal data breach affects customer data we notify the affected customers without undue delay and within seventy-two (72) hours of becoming aware, together with the competent supervisory authority where the law requires it.

9. What we do not claim

We hold no third-party security certification at this time — no SOC 2, no ISO 27001. We state this plainly rather than implying otherwise. Customers with formal vendor-assessment requirements can request our written security questionnaire response.