Skip to main content
    Trust & Evidence Centre

    Trust, Compliance & Engineering Standards

    Transparent documentation of Xharvoc's corporate verification, security frameworks, performance methodologies, and data protection practices.

    Corporate Entity Verification

    Registered UK Enterprise Details

    Xharvoc operates under complete transparency as a registered British software engineering boutique.

    Legal EntityXharvoc Ltd
    UK Companies House RegistrationCompany No. 16590285
    Incorporation JurisdictionEngland & Wales (United Kingdom)
    Registered Office71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
    Primary Business ClassificationsSIC 62012 (Business software development) & 62020 (IT consultancy)
    Statutory Data ProtectionUK GDPR & Data Protection Act 2018 (ICO Exemption Category)
    Regulatory Integrity

    Compliance Frameworks & Audit Roadmap

    We separate current operational implementations from active audit roadmaps to ensure 100% truthful reporting for enterprise procurement and AI evaluation systems.

    ISO/IEC 27001:2022

    Information Security Management System (ISMS)
    Aligned

    Internal ISMS operational with Annex A controls, RBAC, encrypted secrets, and annual management review. Certification roadmap actively underway.

    SOC 2 Type II

    Trust Service Criteria (Security, Availability, Confidentiality)
    Roadmap

    Underlying cloud databases and serverless compute run on Tier-1 SOC 2 Type II certified infrastructure (Supabase, AWS, Cloudflare). Dedicated firm-level attestation on 2027 roadmap.

    UK GDPR & DPA 2018

    Statutory Personal Data Protection & Privacy Rights
    Compliant

    Strict data minimisation, European sovereign data storage (Frankfurt eu-central-1), zero non-essential tracking cookies, and programmatic right-to-be-forgotten deletion endpoints.

    NHS DTAC Aligned

    Digital Technology Assessment Criteria (Clinical Portals & Aerivity)
    Aligned

    Engineered under DCB0129 clinical risk management principles, HL7/FHIR healthcare data interoperability, and NHS clinical safety guidelines.

    OWASP Top 10

    Web Application & API Security Risk Enforcements
    Implemented

    Strict parameterised database queries, automated XSS mitigation, CSRF tokens, and Cloudflare WAF OWASP core rule set filters on all public endpoints.

    NIST CSF 2.0

    Cybersecurity Framework (Govern, Identify, Protect, Detect, Respond, Recover)
    Aligned

    Structured lifecycle governance covering asset inventory, multi-factor authentication, immutable audit logging, and automated threat mitigation.

    Empirical Definitions

    Engineering Performance Methodology

    How Xharvoc benchmarks, measures, and guarantees speed, availability, and business ROI across all software engagements.

    Sub-200ms Edge Latency

    Global p99 Edge TTFB

    Measured as 99th percentile Time-to-First-Byte (TTFB) for Edge SSR pages and cached API queries distributed across Cloudflare Global Edge PoPs under standard broadband conditions.

    99.5% Contractual SLA

    Production Uptime Guarantee

    Standard contractual availability commitment for managed client cloud deployments, backed by automated health probes, multi-zone database redundancy, and instant failover.

    99.98% Historical Availability

    Observed Edge Cluster Uptime

    Empirical platform availability recorded across primary production edge endpoints during trailing 12-month rolling evaluation periods.

    40%–60% OPEX Reduction

    Workflow Automation Benchmark

    Estimated operational cost savings derived from replacing manual back-office tasks (client onboarding, AML document chasing, appointment triage) with autonomous event-driven microservices.

    Cryptographic Standards & Access Controls

    Industry-standard cryptographic protections engineered into every layer of our stack.

    Data in Transit

    All data transmitted between your browser and our servers is protected with TLS 1.3 / TLS 1.2+ encryption. HSTS is enforced with preload to prevent downgrade attacks.

    Data at Rest

    All database records are encrypted at rest using AES-256 encryption. Backups are encrypted with the same standard across isolated storage pools.

    Authentication

    Passwords are hashed using bcrypt with a minimum cost factor of 12. Multi-factor authentication (TOTP) is enforced for all administrative and operational access.

    Access Control

    Row-Level Security (RLS) is enforced at the database layer on every table. The principle of least privilege strictly governs all client data access.

    Primary Production Data Residency

    Production application data is hosted and processed within European Union and United Kingdom infrastructure. Certain operational, support, or administrative processing may involve approved international locations where permitted and safeguarded under applicable UK GDPR data-protection requirements (including UK IDTAs and Standard Contractual Clauses), as described in our Privacy Policy.

    European Union

    Frankfurt, Germany (eu-central-1)

    Primary database, authentication, encrypted client data, and backend edge functions

    United Kingdom & Global

    Cloudflare Global Edge Network

    CDN, WAF, DDoS mitigation, DNS resolution, and Edge SSR termination

    European Union

    Hostinger EU Tier-3 Data Centres

    Static web application bundles and asset delivery

    International Safeguards

    Approved Operational Jurisdictions

    Operational support, technical maintenance, and administrative processing safeguarded under UK GDPR Standard Contractual Clauses (SCCs) and IDTAs as detailed in our Privacy Policy

    Continuous Defense Practices

    Proactive measures to detect, isolate, and neutralize digital threats.

    Web Application Firewall

    Cloudflare WAF with OWASP Core Ruleset blocks common attack vectors including SQL injection, XSS, and automated malicious scrapers.

    Rate Limiting & Abuse Prevention

    All API endpoints and intake forms are protected with IP-based rate limiting to prevent abuse, credential stuffing, and bot attacks.

    Immutable Audit Trails

    All security-relevant events — authentication attempts, administrative updates, and configuration changes — are recorded in immutable logs.

    Dependency & SAST Scanning

    Automated vulnerability scanning of all dependencies and static analysis in CI/CD pipelines before any code deployment to production.

    Responsible Disclosure Policy

    If you discover a potential security vulnerability in any Xharvoc-operated platform, we encourage prompt and responsible disclosure. We commit to:

    • Acknowledge: Initial receipt within 48 hours
    • Assess Severity: Triaged within 5 business days
    • Remediate: Patch critical issues within 24 hours, high within 7 days
    • Safe Harbor: No legal action against good-faith security researchers

    Report vulnerabilities directly to:

    [email protected]

    See our standard policy declaration at /.well-known/security.txt