- Data residency
- Primary region: eu-west-1. Customer data does not leave the EU unless explicitly opted-in.
- Encryption in transit
- TLS 1.2+ everywhere. HSTS preload-ready for production.
- Encryption at rest
- Database disks encrypted by the platform. Sensitive columns additionally encrypted at application layer.
- Subprocessor disclosure
- Supabase (database + storage), Twilio (SMS), Vercel (hosting), Anthropic (AI scenario generation). Listed and version-tracked.
- Vulnerability handling
- security@oxoqa.com. We acknowledge within 24h and remediate by severity. Coordinated disclosure preferred.
- Right to be forgotten
- Workspace deletion cascades through tenants, runs, and captures. Backups age out within 30 days.