Last updated: July 30, 2026

1. Our Approach

This page describes, in plain terms, the security measures Xponzy Tech LLC applies to protect its services and its clients' data. We prefer honesty over marketing: Xponzy does not currently hold formal security certifications such as SOC 2 or ISO 27001, and we do not claim them. What follows is what we actually do. As a small company, we focus on fundamentals done consistently.

2. Encryption in Transit

Connections to our website, client portal, and hosted services are protected with TLS. We keep TLS configurations current, disable obsolete protocol versions on managed endpoints, and support encrypted connections (HTTPS, SMTP with STARTTLS or implicit TLS, IMAP/POP over TLS) for the services we operate.

3. Access Controls and Least Privilege

  • Administrative access to servers and management panels is limited to the personnel who need it for their role, following the principle of least privilege.
  • Each administrator uses individual, non-shared accounts; shared credentials are not used for administrative systems.
  • Strong authentication is required for administrative access, including multi-factor authentication where the platform supports it.
  • Access rights are reviewed periodically and revoked promptly when a role changes or a relationship ends.

4. Employee and Contractor Access

Employees and contractors receive access to client data only when a support or operational task requires it, and only for the duration of that task. All personnel are bound by confidentiality obligations. Access to client accounts through support tooling is logged. We do not ask clients for their passwords; support tasks are performed through administrative interfaces that do not require them.

5. Backups

We perform daily backups of hosted services and of our management systems, retain multiple restore points, and store backup copies separately from the primary systems. Restoration procedures are tested periodically. Backups protect against infrastructure failure and are not a substitute for the client's own copies of critical data, which we recommend maintaining.

6. Monitoring and Logging

We monitor the availability and health of our infrastructure continuously and keep system, authentication, and application logs for security analysis and troubleshooting. Alerts for anomalous conditions are reviewed and acted on. Logs are retained for limited periods appropriate to their purpose, as described in our Privacy Policy.

7. Patching and Hardening

Operating systems, control panels, and server software on managed infrastructure are updated on a regular schedule, with expedited handling for vulnerabilities that are critical or actively exploited. Unnecessary services are disabled, and firewalls restrict traffic to what each system requires. Clients remain responsible for updating the applications they install within their own hosting space, such as content management systems and plugins, and we encourage keeping them current.

8. Vendor Security

We rely on established providers for data centers, network infrastructure, payment processing, and software platforms. Before adopting a vendor that will handle client data, we review its security practices and contractual commitments, and we prefer vendors that publish their own security documentation. Payment card data is handled by our payment processors, Stripe and PayPal, and does not touch our servers.

9. Incident Response

We maintain a simple, documented incident response process: detect and triage the event, contain it, eradicate the cause, restore normal service, and record lessons learned. If an incident affects your data or services, we will inform you through the client portal or the contact details on your account, and, where personal data is involved, we will notify as required by applicable law and by our Data Processing Agreement.

10. Your Part

Security is shared. We recommend that clients use strong, unique passwords, enable two-factor authentication in the client portal where available, keep their own applications updated, and limit the people who have access to their account.

11. Reporting a Security Concern

If you detect a vulnerability or a possible security incident, please report it responsibly through our support portal at https://xponzy.com/submitticket.php. Our Responsible Disclosure policy describes the rules and commitments that apply to good-faith research. General questions about this policy can be sent through our contact form at https://xponzy.com/contact.php.