Trust and security

Security details should match the deployment you are evaluating.

Xillix provides custom reporting services and separate Luxon software products. Their data sources, access methods, hosting, model providers, retention, and operational controls can differ, so security review starts with the exact scope rather than a one-size-fits-all promise.

Public baseline

What this page can confirm

The public website and every customer deployment are different security surfaces. This page states only the baseline that can be described without exposing private configuration or expanding a customer contract.

Scope matters

Different work creates different security questions.

Use the product or project column below to frame an evaluation. Exact controls are confirmed during discovery and contracting.

Surface Publicly described baseline Confirm for your deployment
xillix.io The public marketing site is delivered over HTTPS through Cloudflare. Public form and assistant data should not include passwords, API keys, or sensitive customer records.
NetSuite reporting projects Work begins by identifying customer-approved reports, saved searches, exports, fields, and business rules. Access method, credentials, refresh path, data location, user access, and handoff responsibilities.
Luxon products Each product uses content and workflows approved for that implementation. Authentication, customer isolation, storage, model-provider configuration, retention, logging, backups, and human access.

Evaluation checklist

Questions to settle before data is connected

These items are part of a useful security review. Their presence in this checklist does not mean every option is available in every product or plan.

Data scope

Identify the fields, documents, conversations, and reporting outputs required for the intended result. Exclude data that is not needed.

Access path

Confirm who provides access, what level is needed, how it is revoked, and which customer administrator owns approvals.

Processing path

Document where approved inputs originate, which services process them, and what is returned to users or display screens.

Storage and retention

Confirm what is stored, for how long, how deletion works, and whether a product-specific or contract-specific schedule applies.

Operations

Review monitoring, updates, backups, recovery expectations, support contacts, and incident communication for the selected deployment.

Third parties

Confirm the current hosting, communications, payment, and model providers involved in the selected product or service.

Boundaries

Controls are not interchangeable.

The following items must not be inferred from general marketing copy. Ask for current, product-specific documentation when they matter to your review.

Identity and access

SSO, role design, administrator permissions, session behavior, and dedicated environments are deployment-dependent unless a written agreement says otherwise.

Data handling

Encryption-at-rest details, regional hosting, fixed deletion periods, backup schedules, and model-provider retention settings are not promised by this public page.

Compliance support

A DPA, regulated-data workflow, audit package, or formal certification is not represented as standard or available here. Those items require a separate review.

Report a concern

Start with a low-risk notification.

If you believe you found a security issue, use the contact page or email [email protected] with a short description and a way to reach you. Do not place credentials, customer data, exploit code, or sensitive evidence in the first message. Ask for a secure channel for additional details.

Email a security concern

Need deployment-specific security details?

Describe the product or reporting project you are evaluating and the controls your review requires. Xillix can separate verified capabilities from items that need additional scoping.

Contact Xillix