Data scope
Identify the fields, documents, conversations, and reporting outputs required for the intended result. Exclude data that is not needed.
Trust and security
Xillix provides custom reporting services and separate Luxon software products. Their data sources, access methods, hosting, model providers, retention, and operational controls can differ, so security review starts with the exact scope rather than a one-size-fits-all promise.
Public baseline
The public website and every customer deployment are different security surfaces. This page states only the baseline that can be described without exposing private configuration or expanding a customer contract.
Scope matters
Use the product or project column below to frame an evaluation. Exact controls are confirmed during discovery and contracting.
| Surface | Publicly described baseline | Confirm for your deployment |
|---|---|---|
| xillix.io | The public marketing site is delivered over HTTPS through Cloudflare. | Public form and assistant data should not include passwords, API keys, or sensitive customer records. |
| NetSuite reporting projects | Work begins by identifying customer-approved reports, saved searches, exports, fields, and business rules. | Access method, credentials, refresh path, data location, user access, and handoff responsibilities. |
| Luxon products | Each product uses content and workflows approved for that implementation. | Authentication, customer isolation, storage, model-provider configuration, retention, logging, backups, and human access. |
Evaluation checklist
These items are part of a useful security review. Their presence in this checklist does not mean every option is available in every product or plan.
Identify the fields, documents, conversations, and reporting outputs required for the intended result. Exclude data that is not needed.
Confirm who provides access, what level is needed, how it is revoked, and which customer administrator owns approvals.
Document where approved inputs originate, which services process them, and what is returned to users or display screens.
Confirm what is stored, for how long, how deletion works, and whether a product-specific or contract-specific schedule applies.
Review monitoring, updates, backups, recovery expectations, support contacts, and incident communication for the selected deployment.
Confirm the current hosting, communications, payment, and model providers involved in the selected product or service.
Boundaries
The following items must not be inferred from general marketing copy. Ask for current, product-specific documentation when they matter to your review.
SSO, role design, administrator permissions, session behavior, and dedicated environments are deployment-dependent unless a written agreement says otherwise.
Encryption-at-rest details, regional hosting, fixed deletion periods, backup schedules, and model-provider retention settings are not promised by this public page.
A DPA, regulated-data workflow, audit package, or formal certification is not represented as standard or available here. Those items require a separate review.
Report a concern
If you believe you found a security issue, use the contact page or email [email protected] with a short description and a way to reach you. Do not place credentials, customer data, exploit code, or sensitive evidence in the first message. Ask for a secure channel for additional details.
Describe the product or reporting project you are evaluating and the controls your review requires. Xillix can separate verified capabilities from items that need additional scoping.
Contact Xillix