Security at XBert
Any questions or clarifications can be emailed to security@xbert.io.
1. Operational Infrastructure and Location
Section titled “1. Operational Infrastructure and Location”XBert runs on the Microsoft Azure Public Cloud. Azure has been independently certified to ISO 20000-1:2011, ISO 27001, SOC 2 Type II, and CSA STAR.
Our data centres are in Australia (primary: Australia Southeast; DR: Australia East) and all customer data is maintained within Australian zones.
2. Encryption Standards
Section titled “2. Encryption Standards”All customer and server traffic is encrypted through the use of SSL. Our SSL certificates use 256-bit encryption using TLS 1.3. Data is encrypted at rest with AES-256 block-level storage encryption.
All application secrets, connection strings, and certificates are stored in Azure Key Vault with managed key rotation. Keys are protected by Azure Entra ID access controls with MFA and Conditional Access policies.
For full details, refer to the Data Encryption Policy.
3. User Identity Management
Section titled “3. User Identity Management”XBert uses Auth0 (by Okta), one of the leading providers of identity management, for user identity and user management.
Auth0 is ISO 27001, SOC 2 Type II, ISO 27018, HIPAA BAA, EU-US Privacy Shield Framework, Gold CSA STAR, PCI DSS Certified, and GDPR compliant.
- All access to Azure cloud is protected by multi-factor authentication (MFA) and restricted based on an allowed list of Internet Protocol (IP) addresses
- All applications used by XBert staff are protected by MFA
- Access to Azure Cloud services is controlled by Azure Entra ID with resource grouping and role-based permissions based on job functions and responsibilities
- Privileged accounts are reviewed quarterly and follow the Principle of Least Privilege
For full details, refer to the Privileged Account and Access Management Policy.
4. Financial Security
Section titled “4. Financial Security”Credit card details are never stored by XBert. Credit cards are transmitted directly to our payment providers over SSL connections and are not logged or stored in XBert systems.
- Chargebee: PCI-DSS Level 1 compliant (subscription payments)
- Stripe: PCI-DSS Level 1 compliant (customer payments)
5. Security Management
Section titled “5. Security Management”XBert uses Microsoft Defender for Cloud (formerly Azure Security Center), which provides continuous assessment of our security posture, protects against cyberattacks, and streamlines security management with integrated controls.
Key capabilities:
- Continuous threat detection and vulnerability assessments
- Compliance monitoring against security baselines
- Security alerting integrated with Slack for operational escalation
- Azure Policy enforcement for configuration compliance
For full details, refer to the Network Monitoring and Logging Policy.
6. Release Management
Section titled “6. Release Management”XBert uses Azure DevOps for CI/CD. Our continuous integration and continuous deployment approach incorporates security testing as part of our pipeline process, including:
- Static code analysis and security scanning (OWASP tools)
- Dependency vulnerability scanning (GitHub Dependabot, npm audit, dotnet vulnerable package check)
- Security header scanning
- Automated testing (unit tests, integration tests)
- Peer code review required for all changes (GitHub Pull Requests with branch protection)
All releases follow best-practice branching strategies and code review processes. CI/CD automates builds through development, staging, and production environments using deployment slots for zero-downtime releases.
For full details, refer to the SDLC and SBOM Policy and Patch Management Policy.
7. Accounting Data Integrations
Section titled “7. Accounting Data Integrations”XBert uses a secure OAuth 2.0 connection to allow access to Xero, MYOB, QuickBooks, FreeAgent, Employment Hero, and XPM. We have been independently security audited by Xero and Intuit.
All API communications are encrypted in transit using TLS 1.2+.
8. AI and Artificial Intelligence
Section titled “8. AI and Artificial Intelligence”XBert uses AI capabilities to provide intelligent automation, data analysis, and agent-based workflows for customers. Key details:
- AI providers: OpenAI API and Anthropic Claude, accessed via secure API connections over TLS 1.2+
- Data handling: Financial data sent for AI processing is ephemeral and not stored by the AI provider per our Data Processing Agreement (DPA)
- No training: Customer financial data is never used for AI model training
- Data sovereignty: AI processing requests may flow to US-based API endpoints; however, data is not persisted and returns to Australian-hosted systems
- AI memory: XBert’s AI memory service (Mem0) is hosted on Azure Container Apps within Australia
- Audit trail: AI interactions are logged for quality assurance and compliance review (90-day retention)
- Human oversight: AI-generated recommendations are presented to users for review and action; automated actions require explicit user configuration and approval
9. Operational Monitoring
Section titled “9. Operational Monitoring”We maintain comprehensive monitoring across multiple layers:
- Azure Monitor and Application Insights: Infrastructure and application performance monitoring
- Microsoft Defender for Cloud: Continuous security threat detection
- Sentry: Application error tracking and alerting
- Pingdom: External uptime monitoring of public endpoints
- Slack: Operational staff alerting, escalation, and on-call notifications
For full details, refer to the Network Monitoring and Logging Policy.
10. Incident Response
Section titled “10. Incident Response”XBert maintains a formal Incident Response Plan covering:
- Security incident classification and triage procedures
- Containment, eradication, and recovery procedures
- Customer notification within 24 hours of confirmed data breach
- OAIC notification under the Notifiable Data Breaches scheme
- Post-incident review and lessons learned process
Breach notification: Customers are notified via email within 24 hours of a confirmed data breach. Notification method is email to the client administrator with remediation details.
For full details, refer to the Incident Response Plan.
11. Business Continuity and Disaster Recovery
Section titled “11. Business Continuity and Disaster Recovery”XBert maintains a formal Business Continuity Plan and Disaster Recovery Controls document covering:
- Azure PaaS high availability with multiple Availability Zones within Australia
- Database backups with 28-day Point-in-Time Recovery (PITR) and geo-replication to Australia East
- Application code permanently stored in GitHub for rapid redeployment
- Recovery Time Objective (RTO): < 24 hours
- Annual DR exercises with documented test results
For full details, refer to the Business Continuity Planning and Disaster Recovery Controls document.
12. Data Retention and Privacy
Section titled “12. Data Retention and Privacy”- Customer data is retained for the duration of the subscription
- Data is purged within 30 days of account deletion
- Customers own all their data and have self-service tools to export and delete
- All data handling complies with the Privacy Act 1988 (Cth) and Australian Privacy Principles
For full details, refer to the Data Retention and Disposal Policy.
13. Third-Party Vendor Management
Section titled “13. Third-Party Vendor Management”XBert maintains a vendor register with tiered security assessments:
- Critical vendors (Azure, Auth0, Xero, QuickBooks, MYOB, FreeAgent, OpenAI, Anthropic): Annual security review with continuous monitoring
- High vendors (Chargebee, Stripe, Employment Hero): Annual security review
- All vendors assessed against security, data residency, and compliance requirements
- No third-party vendor has access to customer data unless operationally required and contractually agreed
- All source code is owned and maintained solely by XBert Pty Ltd
For full details, refer to the Third-Party and Vendor Management Policy.
14. Support and Development
Section titled “14. Support and Development”Application development is located within Australia by XBert employees. All employees are under contracts under NSW laws.
Support is provided through Intercom and online meetings. Our support information can be found at support.xbert.io.
15. Compliance
Section titled “15. Compliance”XBert’s security practices align with:
- Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs)
- Notifiable Data Breaches scheme (Part IIIC, Privacy Act)
- GDPR (where applicable to EU/UK customers)
- PCI-DSS (via compliant payment providers)
- ISO 27001 (aligned practices)
- OWASP Secure Development Guidelines
- Azure compliance: ISO 20000-1:2011, CSA STAR, SOC 2
16. Policy Library
Section titled “16. Policy Library”| Policy | Description |
|---|---|
| Data Encryption Policy | Encryption standards for data at rest and in transit |
| Data Retention and Disposal Policy | Retention schedules and secure data disposal |
| Third-Party and Vendor Management Policy | Vendor assessment, monitoring, and risk management |
| Privileged Account and Access Management Policy | Access controls, MFA, privileged account management |
| Network Monitoring and Logging Policy | Monitoring stack, log retention, security alerting |
| Patch Management Policy | Vulnerability remediation and dependency management |
| SDLC and SBOM Policy | Secure development lifecycle and software supply chain |
| Incident Response Plan | Security incident detection, response, and notification |
| Business Continuity and Disaster Recovery Controls | BCP/DR strategy and recovery procedures |
17. Common Questions
Section titled “17. Common Questions”| Question | Answer |
|---|---|
| How are user identities handled? | User Identity management is by Auth0 (ISO 27001, SOC 2 Type II, PCI DSS certified). See Auth0 Security. |
| Is SSO supported? | Yes - OAuth 2.0 using Auth0. SAML 2.0 and OIDC enterprise SSO also available. |
| What type of cloud do you use? | Azure Public Cloud running in Australia (Australia Southeast primary, Australia East DR) |
| By whom and how is source code maintained? | All source code is owned and maintained by XBert Pty Ltd in private GitHub repositories. Source code has never been shared with any third-party. |
| How do you review application security? | Automated scanning in CI/CD (OWASP tools, Dependabot), peer code review, annual penetration testing. |
| Where is data stored? Is it replicated? | Microsoft Azure data centres in Australia. Backups geo-replicated within Australia. |
| Who owns the data? | Clients own all data. Self-service tools available for export and deletion. |
| Is data at rest encrypted? | Yes - AES-256 Transparent Data Encryption on all databases and storage. |
| Is AI data stored or used for training? | No. AI processing data is ephemeral (not stored by provider per DPA). Never used for model training. |
| What is your breach notification timeframe? | Customer admin notified via email within 24 hours of confirmed breach. OAIC notified per NDB scheme requirements. |
| What are your recovery time objectives? | < 24 hours RTO. 28-day PITR for databases. |
Any further questions or clarifications can be emailed to security@xbert.io.
18. Change History
Section titled “18. Change History”| Version | Date | Changes |
|---|---|---|
| 1.0 | 2020 | Initial creation |
| 2.0 | December 2024 | Updated security controls and compliance framework |
| 3.0 | April 2026 | Major update: Added AI governance, incident response, vendor management, and compliance sections |