Security & Trust

OUR COMMITMENT

Security & Transparency by Design

At Epixet Technologies, we build security, privacy, and reliability into every layer of our platform. Enterprise-grade protection without compromising user experience.

COMPLIANCE & CERTIFICATIONS

We Meet Global Standards

NDPA / GAID

Fully compliant with Nigeria Data Protection Act 2023 and GAID 2025.

GDPR Ready

Data protection measures aligned with EU General Data Protection Regulation.

PCI DSS

Payment processing via PCI DSS Level 1 compliant partners (Flutterwave, Paystack).

SOC 2 Type II

In progress — auditing for SOC 2 compliance in 2026.

SECURITY OVERVIEW

How We Protect Your Data

Encryption at Rest & In Transit

AES-256 encryption for data at rest. TLS 1.2+ for all data in transit.

Access Control & MFA

Role-based access control (RBAC) with multi-factor authentication support.

Tenant Isolation

Logical separation ensures Tenant data is never accessible by other Tenants.

Regular Backups

Automated daily backups with 90-day retention for disaster recovery.

Vulnerability Scanning

Regular penetration testing and automated vulnerability assessments.

24/7 Monitoring

Real-time security monitoring and incident response protocols.

RELIABILITY

99.9% Uptime Guarantee

Enterprise SLA

99.9% uptime commitment for our multi-tenant cloud environment. Scheduled maintenance communicated 48 hours in advance.

User-Controlled Updates

When a new version is deployed, users choose when to reload — no forced interruptions. Continue working or update immediately.

TRANSPARENCY

Our Sub-processors

We use trusted third-party providers to deliver the Epixet BOS platform. Each sub-processor is bound by data protection obligations consistent with our DPA.

Sub-processor Service Data Processed Location
Hetzner Online GmbHPhysical infrastructure (bare-metal servers)All platform dataHelsinki, Finland
Truehost CloudManagement layer / resellerManagement metadataKenya / Nigeria
AWS CloudFrontContent Delivery Network (CDN)IP addresses, request metadataGlobal
Cloudflare, Inc.CDN, DDoS protection, DNS proxyIP addresses, security metadataGlobal
Backblaze, Inc.File & object storageUser-uploaded filesAmsterdam, Netherlands
Flutterwave / PaystackPayment processingPayment details (PCI DSS)Nigeria, US, Uganda
Zoho CorporationTransactional emailNames, email addressesGlobal
Google LLC (Analytics)Usage analytics (anonymized)Anonymized usage dataGlobal

For the complete legal Annex B, please refer to our Terms of Use (Part III – DPA).

FREQUENTLY ASKED QUESTIONS

Security FAQs

Where is my data stored?

Your data is stored on servers located in Helsinki, Finland (Hetzner Online GmbH data center).

Is my data encrypted?

Yes. AES-256 encryption for data at rest. TLS 1.2+ for all data in transit.

Do you have a Data Processing Agreement (DPA)?

Yes. A DPA is available as Part III of our Terms of Use. Contact us for a signed copy.

How do I report a security vulnerability?

Email our security team at security@epixet.com. We practice responsible disclosure.

Is Epixet GDPR compliant?

Yes. Our data protection measures are aligned with GDPR requirements, and we offer a DPA for EU customers.

How long do you retain my data?

For the duration of your active subscription, plus up to 90 days post-termination unless deletion is requested.

CONTACT

Have Security Questions?

Contact our security team or Data Protection Officer (DPO) directly.

Security Team: security@epixet.com
DPO (Data Protection Officer): dpo@epixet.com