Encryption · EU residency · GDPR · SOC 2 in progress

Security at XP One

XP One is built for enterprise-grade security. EU data residency by default. TLS 1.2+ in transit. AES-256 at rest. GDPR-compliant from day one. SOC 2 Type II audit in progress for Q3 2026. Full transparency on sub-processors, encryption, and disclosure policy below.

GDPR-compliant EU data residency TLS 1.2+ / AES-256 SOC 2 in progress DPA available
// DATA RESIDENCY

Where your data lives.

EU-hosted by default. Custom regional setups available on enterprise plans.

TierDefault regionProviderOptional region
SoloEU (Frankfurt)AWS eu-central-1
GrowthEU (Frankfurt)AWS eu-central-1
ScaleEU (Frankfurt)AWS eu-central-1US (N. Virginia) — AWS us-east-1, on request

All customer data — leads, sequences, conversations, integrations, billing — is stored on EU-hosted infrastructure by design. Formal EU data-residency certification (AWS Frankfurt) is planned for Q3 2026.

// ENCRYPTION

Encryption
at every layer.

// ENC_01
In transit

TLS 1.2+

All traffic between your browser, the XP One app, and our APIs is encrypted with TLS 1.2 or higher. TLS 1.3 preferred. HSTS enabled. Strict transport security policy enforced at the Cloudflare edge.

// ENC_02
At rest

AES-256

All customer data at rest — databases, file storage, backups, logs — is encrypted with AES-256. Encryption keys are managed by AWS KMS with automatic rotation. Keys never leave the EU residency region.

// ENC_03
Secrets

Credential storage

OAuth tokens, LinkedIn cookies, SMTP credentials, and integration API keys are encrypted with a per-tenant data key, wrapped by a master key in AWS KMS. Credentials are never logged, never displayed, never accessible to XP One staff in plaintext.

// COMPLIANCE

Compliance
status.

Honest, current, no overclaiming.

StandardStatusNotes
GDPR (EU 2016/679)✓ CompliantCompliant from day one. EU data residency. DPA available on request.
CCPA (California)✓ CompliantRight to access, delete, opt-out of sale honored. We do not sell personal data.
SOC 2 Type IIIn progressAudit window opened Q1 2026. Type II report targeted for Q3 2026. Type I letter available on request.
ISO 27001On roadmapRoadmap item for 2027. Not yet certified. Do not represent us as ISO 27001 certified.
HIPAANot supportedXP One is not a HIPAA-eligible product. Do not process PHI through XP One.
UK Data Protection Act 2018✓ CompliantCompliant. LeadsMind AI LTD is registered in the UK.
// SUB-PROCESSORS

Who else
touches your data.

Full transparency. Every sub-processor, what they do, where they sit.

Sub-processorPurposeData processedRegion
Amazon Web Services (AWS)Application hosting, database, storage, KMSAll customer dataEU Frankfurt (default)
CloudflareCDN, edge security, DDoS protectionHTTP request metadata, IP addressesGlobal edge · EU/US routing
StripeBilling, subscriptions, taxCustomer name, email, billing address, card data (Stripe-hosted)EU (Ireland) · US
PostmarkTransactional email (signup, password reset, invoices)Customer email, transactional contentUS (with EU options on request)
OpenAILLM inference for AI agent features (drafting, classification)Sequence content, reply content — opt-out available on requestUS · zero data retention agreement

We notify customers in advance of any new sub-processor via email and changelog. Customers may object to new sub-processors before they go live. The full, current sub-processor list is available on request.

// AUTHENTICATION

Authentication.

Email/password for everyone. SSO/SAML for enterprise.

// AUTH_01
All tiers

Email + password

Passwords are hashed with bcrypt (cost factor 12). Minimum 10 characters. Common-password rejection. Rate-limited login. Email-based recovery only.

// AUTH_02
All tiers

Two-factor (2FA)

TOTP-based 2FA (Google Authenticator, 1Password, Authy) available on all tiers. Recommended for all admin accounts. Enforced at account-owner discretion.

// AUTH_03
Custom enterprise

SSO / SAML 2.0

SAML 2.0 single sign-on for Okta, Azure AD, Google Workspace, JumpCloud. SCIM provisioning supported. Just-in-time user creation. Available on Growth tier.

// VULNERABILITY DISCLOSURE

Responsible
disclosure.

Found a security issue? Tell us first. We'll respond within 48 hours.

// CONTACT

[email protected]

Report vulnerabilities directly to [email protected]. Include a clear description, steps to reproduce, and impact. PGP key available on request.

Our commitment

We acknowledge receipt within 48 hours. We will not pursue legal action against researchers acting in good faith. We will credit you in a public disclosure (or keep you anonymous, your choice).

Disclosure window

We ask researchers to wait up to 90 days from the date of report before any public disclosure, to allow us time to ship a fix and notify affected customers.

Out of scope

Social engineering, physical attacks, DDoS, attacks on third-party services we don't operate, and reports requiring a rooted/jailbroken device are out of scope.

// LEGAL & PROCUREMENT

DPA, sub-processors,
security questionnaires.

// DOC_01
DPA

Data Processing Agreement

A GDPR-compliant DPA is available on request. Standard Contractual Clauses (SCCs) included for international transfers. Counter-signature within 5 business days. Email [email protected].

// DOC_02
Security review

Vendor questionnaires

We complete SIG, CAIQ, and custom security questionnaires for Scale-tier customers. Turnaround: 5 business days for standard questionnaires, 10 days for custom. Email [email protected].

// DOC_03
Sub-processors

Sub-processor list

The current sub-processor list is published on this page. Customers may subscribe to advance email notifications of any change. Scale-tier customers have a 30-day objection window.

// BUG BOUNTY & STATUS

Coming next.

// ROADMAP_01
2026 H2

Bug bounty program

XP One does not yet run a paid bug bounty. A public program with HackerOne is planned for the second half of 2026, contingent on SOC 2 Type II completion. Until then, responsible disclosure is rewarded with public credit and XP One swag.

// ROADMAP_02
2026

Public status page

A real-time status page at status.xp-one.io is being built. It will publish uptime, incident history, scheduled maintenance, and sub-processor health. Subscribe via email or RSS once live.

// SECURITY CONTACT

One inbox.
Fast response.

For security reports, DPA requests, sub-processor questions, and procurement reviews.

[email protected]

Data protection: [email protected] · Privacy policy: /legal/privacy · DPA: /legal/dpa