Skip to content

Security at XBert

Any questions or clarifications can be emailed to security@xbert.io.

1. Operational Infrastructure and Location

Section titled “1. Operational Infrastructure and Location”

XBert runs on the Microsoft Azure Public Cloud. Azure has been independently certified to ISO 20000-1:2011, ISO 27001, SOC 2 Type II, and CSA STAR.

Our data centres are in Australia (primary: Australia Southeast; DR: Australia East) and all customer data is maintained within Australian zones.

All customer and server traffic is encrypted through the use of SSL. Our SSL certificates use 256-bit encryption using TLS 1.3. Data is encrypted at rest with AES-256 block-level storage encryption.

All application secrets, connection strings, and certificates are stored in Azure Key Vault with managed key rotation. Keys are protected by Azure Entra ID access controls with MFA and Conditional Access policies.

For full details, refer to the Data Encryption Policy.

XBert uses Auth0 (by Okta), one of the leading providers of identity management, for user identity and user management.

Auth0 is ISO 27001, SOC 2 Type II, ISO 27018, HIPAA BAA, EU-US Privacy Shield Framework, Gold CSA STAR, PCI DSS Certified, and GDPR compliant.

  • All access to Azure cloud is protected by multi-factor authentication (MFA) and restricted based on an allowed list of Internet Protocol (IP) addresses
  • All applications used by XBert staff are protected by MFA
  • Access to Azure Cloud services is controlled by Azure Entra ID with resource grouping and role-based permissions based on job functions and responsibilities
  • Privileged accounts are reviewed quarterly and follow the Principle of Least Privilege

For full details, refer to the Privileged Account and Access Management Policy.

Credit card details are never stored by XBert. Credit cards are transmitted directly to our payment providers over SSL connections and are not logged or stored in XBert systems.

  • Chargebee: PCI-DSS Level 1 compliant (subscription payments)
  • Stripe: PCI-DSS Level 1 compliant (customer payments)

XBert uses Microsoft Defender for Cloud (formerly Azure Security Center), which provides continuous assessment of our security posture, protects against cyberattacks, and streamlines security management with integrated controls.

Key capabilities:

  • Continuous threat detection and vulnerability assessments
  • Compliance monitoring against security baselines
  • Security alerting integrated with Slack for operational escalation
  • Azure Policy enforcement for configuration compliance

For full details, refer to the Network Monitoring and Logging Policy.

XBert uses Azure DevOps for CI/CD. Our continuous integration and continuous deployment approach incorporates security testing as part of our pipeline process, including:

  • Static code analysis and security scanning (OWASP tools)
  • Dependency vulnerability scanning (GitHub Dependabot, npm audit, dotnet vulnerable package check)
  • Security header scanning
  • Automated testing (unit tests, integration tests)
  • Peer code review required for all changes (GitHub Pull Requests with branch protection)

All releases follow best-practice branching strategies and code review processes. CI/CD automates builds through development, staging, and production environments using deployment slots for zero-downtime releases.

For full details, refer to the SDLC and SBOM Policy and Patch Management Policy.

XBert uses a secure OAuth 2.0 connection to allow access to Xero, MYOB, QuickBooks, FreeAgent, Employment Hero, and XPM. We have been independently security audited by Xero and Intuit.

All API communications are encrypted in transit using TLS 1.2+.

XBert uses AI capabilities to provide intelligent automation, data analysis, and agent-based workflows for customers. Key details:

  • AI providers: OpenAI API and Anthropic Claude, accessed via secure API connections over TLS 1.2+
  • Data handling: Financial data sent for AI processing is ephemeral and not stored by the AI provider per our Data Processing Agreement (DPA)
  • No training: Customer financial data is never used for AI model training
  • Data sovereignty: AI processing requests may flow to US-based API endpoints; however, data is not persisted and returns to Australian-hosted systems
  • AI memory: XBert’s AI memory service (Mem0) is hosted on Azure Container Apps within Australia
  • Audit trail: AI interactions are logged for quality assurance and compliance review (90-day retention)
  • Human oversight: AI-generated recommendations are presented to users for review and action; automated actions require explicit user configuration and approval

We maintain comprehensive monitoring across multiple layers:

  • Azure Monitor and Application Insights: Infrastructure and application performance monitoring
  • Microsoft Defender for Cloud: Continuous security threat detection
  • Sentry: Application error tracking and alerting
  • Pingdom: External uptime monitoring of public endpoints
  • Slack: Operational staff alerting, escalation, and on-call notifications

For full details, refer to the Network Monitoring and Logging Policy.

XBert maintains a formal Incident Response Plan covering:

  • Security incident classification and triage procedures
  • Containment, eradication, and recovery procedures
  • Customer notification within 24 hours of confirmed data breach
  • OAIC notification under the Notifiable Data Breaches scheme
  • Post-incident review and lessons learned process

Breach notification: Customers are notified via email within 24 hours of a confirmed data breach. Notification method is email to the client administrator with remediation details.

For full details, refer to the Incident Response Plan.

11. Business Continuity and Disaster Recovery

Section titled “11. Business Continuity and Disaster Recovery”

XBert maintains a formal Business Continuity Plan and Disaster Recovery Controls document covering:

  • Azure PaaS high availability with multiple Availability Zones within Australia
  • Database backups with 28-day Point-in-Time Recovery (PITR) and geo-replication to Australia East
  • Application code permanently stored in GitHub for rapid redeployment
  • Recovery Time Objective (RTO): < 24 hours
  • Annual DR exercises with documented test results

For full details, refer to the Business Continuity Planning and Disaster Recovery Controls document.

  • Customer data is retained for the duration of the subscription
  • Data is purged within 30 days of account deletion
  • Customers own all their data and have self-service tools to export and delete
  • All data handling complies with the Privacy Act 1988 (Cth) and Australian Privacy Principles

For full details, refer to the Data Retention and Disposal Policy.

XBert maintains a vendor register with tiered security assessments:

  • Critical vendors (Azure, Auth0, Xero, QuickBooks, MYOB, FreeAgent, OpenAI, Anthropic): Annual security review with continuous monitoring
  • High vendors (Chargebee, Stripe, Employment Hero): Annual security review
  • All vendors assessed against security, data residency, and compliance requirements
  • No third-party vendor has access to customer data unless operationally required and contractually agreed
  • All source code is owned and maintained solely by XBert Pty Ltd

For full details, refer to the Third-Party and Vendor Management Policy.

Application development is located within Australia by XBert employees. All employees are under contracts under NSW laws.

Support is provided through Intercom and online meetings. Our support information can be found at support.xbert.io.

XBert’s security practices align with:

  • Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs)
  • Notifiable Data Breaches scheme (Part IIIC, Privacy Act)
  • GDPR (where applicable to EU/UK customers)
  • PCI-DSS (via compliant payment providers)
  • ISO 27001 (aligned practices)
  • OWASP Secure Development Guidelines
  • Azure compliance: ISO 20000-1:2011, CSA STAR, SOC 2
PolicyDescription
Data Encryption PolicyEncryption standards for data at rest and in transit
Data Retention and Disposal PolicyRetention schedules and secure data disposal
Third-Party and Vendor Management PolicyVendor assessment, monitoring, and risk management
Privileged Account and Access Management PolicyAccess controls, MFA, privileged account management
Network Monitoring and Logging PolicyMonitoring stack, log retention, security alerting
Patch Management PolicyVulnerability remediation and dependency management
SDLC and SBOM PolicySecure development lifecycle and software supply chain
Incident Response PlanSecurity incident detection, response, and notification
Business Continuity and Disaster Recovery ControlsBCP/DR strategy and recovery procedures

QuestionAnswer
How are user identities handled?User Identity management is by Auth0 (ISO 27001, SOC 2 Type II, PCI DSS certified). See Auth0 Security.
Is SSO supported?Yes - OAuth 2.0 using Auth0. SAML 2.0 and OIDC enterprise SSO also available.
What type of cloud do you use?Azure Public Cloud running in Australia (Australia Southeast primary, Australia East DR)
By whom and how is source code maintained?All source code is owned and maintained by XBert Pty Ltd in private GitHub repositories. Source code has never been shared with any third-party.
How do you review application security?Automated scanning in CI/CD (OWASP tools, Dependabot), peer code review, annual penetration testing.
Where is data stored? Is it replicated?Microsoft Azure data centres in Australia. Backups geo-replicated within Australia.
Who owns the data?Clients own all data. Self-service tools available for export and deletion.
Is data at rest encrypted?Yes - AES-256 Transparent Data Encryption on all databases and storage.
Is AI data stored or used for training?No. AI processing data is ephemeral (not stored by provider per DPA). Never used for model training.
What is your breach notification timeframe?Customer admin notified via email within 24 hours of confirmed breach. OAIC notified per NDB scheme requirements.
What are your recovery time objectives?< 24 hours RTO. 28-day PITR for databases.

Any further questions or clarifications can be emailed to security@xbert.io.

VersionDateChanges
1.02020Initial creation
2.0December 2024Updated security controls and compliance framework
3.0April 2026Major update: Added AI governance, incident response, vendor management, and compliance sections