Security at XPOrders

Trust is central to a product that connects to user inboxes. XPOrders is being designed around controlled access, protected infrastructure, and transparent data handling.

Secure account connections

Supported email accounts connect using OAuth. XPOrders does not ask for or store your email password.

Least-privilege access

Requested permissions should be limited to those required for the supported product experience. Permission descriptions should clearly explain why access is needed.

Data isolation

User data should be isolated through application-level authorization and database security policies. Administrative access should be limited and logged.

Secrets and credentials

Privileged keys and service credentials must never be embedded in the public web or mobile application. Sensitive operations should run in trusted server environments.

Monitoring and response

Production systems should include error tracking, infrastructure monitoring, access logging, and a documented process for reviewing security incidents.

Report a concern

Security concerns may be reported to security@xporders.com.