Security at XPOrders
Trust is central to a product that connects to user inboxes. XPOrders is being designed around controlled access, protected infrastructure, and transparent data handling.
Secure account connections
Supported email accounts connect using OAuth. XPOrders does not ask for or store your email password.
Least-privilege access
Requested permissions should be limited to those required for the supported product experience. Permission descriptions should clearly explain why access is needed.
Data isolation
User data should be isolated through application-level authorization and database security policies. Administrative access should be limited and logged.
Secrets and credentials
Privileged keys and service credentials must never be embedded in the public web or mobile application. Sensitive operations should run in trusted server environments.
Monitoring and response
Production systems should include error tracking, infrastructure monitoring, access logging, and a documented process for reviewing security incidents.
Report a concern
Security concerns may be reported to security@xporders.com.
