Security Policy
Last updated: December 9, 2024
Xokth Dhren is committed to protecting the security of our platform, our users, and the data entrusted to us. This Security Policy describes the measures we implement to safeguard information, the responsibilities of users, and the procedures we follow when security incidents occur. By using our services, you acknowledge and agree to the practices described in this document.
1. Scope
This policy applies to all systems, services, infrastructure, and data managed by Xokth Dhren, including our website at xokthdhren.com, associated subdomains, backend services, and any third-party integrations used to deliver our platform. It applies to all users, administrators, employees, and contractors who interact with our systems in any capacity.
2. Data Protection Principles
We approach data security according to the following core principles:
- Confidentiality: Access to sensitive data is restricted to authorized individuals only, based on the principle of least privilege.
- Integrity: We implement controls to ensure that data is not altered or corrupted without authorization.
- Availability: We maintain redundancy and monitoring to ensure that services remain accessible and reliable.
- Accountability: All access and actions on sensitive systems are logged and attributable to specific actors.
3. Infrastructure Security
3.1 Network Security
Our infrastructure is protected by multiple layers of network security controls, including firewalls, intrusion detection systems, and traffic filtering. Access to internal systems is restricted by network segmentation and role-based access controls. All administrative access to production environments is conducted over encrypted channels.
3.2 Server and Hosting Security
We deploy our services on hardened server environments. Operating systems and software dependencies are kept up to date with security patches applied on a regular schedule. Unnecessary services and ports are disabled by default. Server configurations are reviewed periodically against established security benchmarks.
3.3 Physical Security
Physical access to servers and data center infrastructure is managed by our hosting providers, who maintain industry-standard physical access controls including surveillance, access logging, and restricted entry. Xokth Dhren does not operate its own data centers.
4. Data Encryption
All data transmitted between users and our platform is encrypted using TLS (Transport Layer Security) with a minimum version of TLS 1.2. Sensitive data stored at rest, including user credentials and personal information, is encrypted using industry-standard encryption algorithms. Encryption keys are managed securely and rotated according to established schedules.
5. Authentication and Access Control
5.1 User Authentication
User accounts are protected by password-based authentication. Passwords are stored using strong one-way hashing algorithms with per-user salts. We encourage users to choose strong, unique passwords and to avoid reusing credentials across services. Where available, multi-factor authentication is offered as an additional layer of protection.
5.2 Administrative Access
Access to administrative systems is granted only to personnel who require it to perform their duties. Administrative accounts use strong authentication mechanisms and are reviewed regularly. Inactive accounts are disabled promptly. All administrative actions are logged for audit purposes.
5.3 Session Management
User sessions are managed using secure, randomly generated tokens. Sessions expire after a defined period of inactivity. Sensitive operations may require re-authentication. Session tokens are transmitted only over encrypted connections and are invalidated upon logout.
6. Application Security
6.1 Secure Development Practices
Our development team follows secure coding standards throughout the software development lifecycle. Code changes undergo review processes before deployment. We integrate security testing into our development pipeline, including automated scanning for common vulnerability classes such as injection flaws, cross-site scripting, and insecure configurations.
6.2 Vulnerability Management
We conduct periodic vulnerability assessments of our platform and infrastructure. Identified vulnerabilities are prioritized based on severity and remediated within timeframes appropriate to their risk level. We monitor security advisories relevant to the technologies we use and apply patches promptly.
6.3 Third-Party Dependencies
We monitor third-party libraries and components used in our platform for known vulnerabilities. Dependencies are updated regularly, and we evaluate the security posture of critical third-party services before integration.
7. Monitoring and Logging
Our systems are continuously monitored for anomalous activity, unauthorized access attempts, and performance degradation. Security-relevant events are logged with sufficient detail to support investigation and audit. Logs are stored securely, protected from unauthorized modification, and retained for a defined period. Alerts are configured to notify our security team of conditions that may indicate a security incident.
8. Incident Response
8.1 Detection and Containment
When a potential security incident is detected, our team initiates an immediate assessment to determine the nature and scope of the event. Affected systems may be isolated or restricted to prevent further impact while the investigation proceeds.
8.2 Investigation and Remediation
We conduct a thorough investigation of confirmed incidents to identify root causes and affected data or systems. Remediation steps are implemented to address vulnerabilities and restore normal operation. Post-incident reviews are conducted to improve our defenses and response procedures.
8.3 Notification
In the event of a security incident that affects user data, we will notify affected users in a timely manner through available contact channels. Notifications will include a description of the incident, the type of data potentially affected, and the steps we are taking in response. We will also fulfill any notification obligations required by applicable legal or regulatory frameworks.
9. User Responsibilities
Users of the Xokth Dhren platform share responsibility for maintaining security. We ask that all users:
- Use strong, unique passwords for their accounts and do not share credentials with others.
- Keep their account contact information current so that security notifications can be delivered.
- Report any suspicious activity, unauthorized access, or potential vulnerabilities to us promptly.
- Avoid accessing the platform from unsecured or public networks without appropriate precautions.
- Refrain from attempting to probe, test, or exploit any part of our infrastructure without explicit written authorization.
- Keep their own devices and software up to date with security patches.
10. Responsible Disclosure
We welcome reports from security researchers and users who identify potential vulnerabilities in our platform. If you believe you have discovered a security issue, please contact us at support@xokthdhren.com with a detailed description of the issue. We ask that you:
- Provide sufficient information for us to reproduce and investigate the issue.
- Avoid accessing, modifying, or disclosing data belonging to other users.
- Refrain from publicly disclosing the vulnerability until we have had a reasonable opportunity to investigate and remediate it.
We will acknowledge receipt of your report, keep you informed of our progress, and work toward a resolution in good faith. We do not pursue legal action against researchers who act in accordance with these guidelines.
11. Third-Party Services
We may use third-party service providers to support the delivery of our platform, including hosting, analytics, payment processing, and communication services. We evaluate the security practices of these providers before engagement and require that they maintain appropriate security standards. We are not responsible for the independent security practices of third-party services outside our direct control.
12. Backup and Recovery
We maintain regular backups of critical data and system configurations. Backups are stored securely and tested periodically to verify that data can be restored effectively. Our recovery procedures are designed to minimize service disruption in the event of data loss or system failure.
13. Employee Security
Personnel with access to user data or production systems are subject to security awareness training and internal security policies. Access rights are granted based on job responsibilities and reviewed regularly. Upon termination of employment or contract, access is revoked promptly. Employees are required to handle user data with confidentiality and to report any suspected security concerns through internal channels.
14. Changes to This Policy
We may update this Security Policy from time to time to reflect changes in our practices, technology, or applicable requirements. When we make material changes, we will update the date at the top of this document and may notify users through appropriate channels. Continued use of our services following any update constitutes acceptance of the revised policy. We encourage you to review this policy periodically.
15. Contact
If you have questions, concerns, or reports related to the security of our platform, please contact us using the information below:
| Channel | Details |
|---|---|
| support@xokthdhren.com | |
| Phone | +380 44 379 0039 |
| Address | 59/2, Henerala Chuprynky St, Lviv, Lviv Oblast, Ukraine, 79000 |