Security
You handle sensitive client and financial data. Xcentrix is built to keep every firm — and every client — separate and secure.
State only what's genuinely true of your setup. Remove any line you can't stand behind, and don't claim a certification (e.g. ISO 27001, SOC 2, Cyber Essentials) until you actually hold it. Fill the [PLACEHOLDERS].
Data isolation
- Every firm's data is logically separated — no firm can access another's.
- Within a firm, staff and clients see only what their role permits; clients see only their own information.
Encryption & hosting
- Data encrypted in transit (TLS) and at rest.
- Hosted on secure [UK/EU]‑region infrastructure with [provider, e.g. Supabase/AWS].
- Automated backups with [retention period].
Access control
- Role‑based access for owners, staff and clients.
- Row‑level security enforced at the database, not just the interface.
- [If offered: SSO, 2FA, session controls.]
Privacy & compliance
- UK GDPR aligned — data export, retention controls and deletion built in.
- A limited set of vetted sub‑processors, listed on request.
- Data Processing Agreement available for customers.
Reporting a vulnerability
If you believe you've found a security issue, please email security@xcentrixpm.com. We'll acknowledge and investigate promptly.