Trust, Compliance & Engineering Standards
Transparent documentation of Xharvoc's corporate verification, security frameworks, performance methodologies, and data protection practices.
Registered UK Enterprise Details
Xharvoc operates under complete transparency as a registered British software engineering boutique.
Compliance Frameworks & Audit Roadmap
We separate current operational implementations from active audit roadmaps to ensure 100% truthful reporting for enterprise procurement and AI evaluation systems.
ISO/IEC 27001:2022
Information Security Management System (ISMS)Internal ISMS operational with Annex A controls, RBAC, encrypted secrets, and annual management review. Certification roadmap actively underway.
SOC 2 Type II
Trust Service Criteria (Security, Availability, Confidentiality)Underlying cloud databases and serverless compute run on Tier-1 SOC 2 Type II certified infrastructure (Supabase, AWS, Cloudflare). Dedicated firm-level attestation on 2027 roadmap.
UK GDPR & DPA 2018
Statutory Personal Data Protection & Privacy RightsStrict data minimisation, European sovereign data storage (Frankfurt eu-central-1), zero non-essential tracking cookies, and programmatic right-to-be-forgotten deletion endpoints.
NHS DTAC Aligned
Digital Technology Assessment Criteria (Clinical Portals & Aerivity)Engineered under DCB0129 clinical risk management principles, HL7/FHIR healthcare data interoperability, and NHS clinical safety guidelines.
OWASP Top 10
Web Application & API Security Risk EnforcementsStrict parameterised database queries, automated XSS mitigation, CSRF tokens, and Cloudflare WAF OWASP core rule set filters on all public endpoints.
NIST CSF 2.0
Cybersecurity Framework (Govern, Identify, Protect, Detect, Respond, Recover)Structured lifecycle governance covering asset inventory, multi-factor authentication, immutable audit logging, and automated threat mitigation.
Engineering Performance Methodology
How Xharvoc benchmarks, measures, and guarantees speed, availability, and business ROI across all software engagements.
Global p99 Edge TTFB
Measured as 99th percentile Time-to-First-Byte (TTFB) for Edge SSR pages and cached API queries distributed across Cloudflare Global Edge PoPs under standard broadband conditions.
Production Uptime Guarantee
Standard contractual availability commitment for managed client cloud deployments, backed by automated health probes, multi-zone database redundancy, and instant failover.
Observed Edge Cluster Uptime
Empirical platform availability recorded across primary production edge endpoints during trailing 12-month rolling evaluation periods.
Workflow Automation Benchmark
Estimated operational cost savings derived from replacing manual back-office tasks (client onboarding, AML document chasing, appointment triage) with autonomous event-driven microservices.
Cryptographic Standards & Access Controls
Industry-standard cryptographic protections engineered into every layer of our stack.
Data in Transit
All data transmitted between your browser and our servers is protected with TLS 1.3 / TLS 1.2+ encryption. HSTS is enforced with preload to prevent downgrade attacks.
Data at Rest
All database records are encrypted at rest using AES-256 encryption. Backups are encrypted with the same standard across isolated storage pools.
Authentication
Passwords are hashed using bcrypt with a minimum cost factor of 12. Multi-factor authentication (TOTP) is enforced for all administrative and operational access.
Access Control
Row-Level Security (RLS) is enforced at the database layer on every table. The principle of least privilege strictly governs all client data access.
Primary Production Data Residency
Production application data is hosted and processed within European Union and United Kingdom infrastructure. Certain operational, support, or administrative processing may involve approved international locations where permitted and safeguarded under applicable UK GDPR data-protection requirements (including UK IDTAs and Standard Contractual Clauses), as described in our Privacy Policy.
Frankfurt, Germany (eu-central-1)
Primary database, authentication, encrypted client data, and backend edge functions
Cloudflare Global Edge Network
CDN, WAF, DDoS mitigation, DNS resolution, and Edge SSR termination
Hostinger EU Tier-3 Data Centres
Static web application bundles and asset delivery
Approved Operational Jurisdictions
Operational support, technical maintenance, and administrative processing safeguarded under UK GDPR Standard Contractual Clauses (SCCs) and IDTAs as detailed in our Privacy Policy
Continuous Defense Practices
Proactive measures to detect, isolate, and neutralize digital threats.
Web Application Firewall
Cloudflare WAF with OWASP Core Ruleset blocks common attack vectors including SQL injection, XSS, and automated malicious scrapers.
Rate Limiting & Abuse Prevention
All API endpoints and intake forms are protected with IP-based rate limiting to prevent abuse, credential stuffing, and bot attacks.
Immutable Audit Trails
All security-relevant events — authentication attempts, administrative updates, and configuration changes — are recorded in immutable logs.
Dependency & SAST Scanning
Automated vulnerability scanning of all dependencies and static analysis in CI/CD pipelines before any code deployment to production.
Responsible Disclosure Policy
If you discover a potential security vulnerability in any Xharvoc-operated platform, we encourage prompt and responsible disclosure. We commit to:
- Acknowledge: Initial receipt within 48 hours
- Assess Severity: Triaged within 5 business days
- Remediate: Patch critical issues within 24 hours, high within 7 days
- Safe Harbor: No legal action against good-faith security researchers
Report vulnerabilities directly to:
[email protected]See our standard policy declaration at /.well-known/security.txt