On this page
XXtrusioDocs

DocsAccount, security and plan

Understand Xtrusio Access Controls and Data Handling

Use approved account and data-handling policies to establish access responsibilities and available controls.

Availability and responsibility

Use approved account and data-handling policies to establish access responsibilities and available controls. The shared implementation supports Firebase email/password and Google sign-in, provisioned access, server-enforced roles and feature permissions, and account disabling with refresh-token revocation. Stored provider-key overrides use AES-256-GCM encryption. The deployment architecture uses Cloudflare and Firebase with separate client deployments. These controls do not establish independent certification or a complete security audit. Confirm the controls enabled in the applicable deployment.

Establish the account boundaries

Identify who can view client data, approve content, publish, manage users and configure integrations. Ask how support access is granted and reviewed. Confirm retention and deletion behavior through the approved policy rather than assuming that removing a visible row deletes every copy.

Review the controls

  1. Obtain the approved account and data-handling information.
  2. Confirm available authentication methods.
  3. Test relevant roles using an authorized non-production procedure.
  4. Review integration permissions and secret handling.
  5. Confirm retention, deletion and support-access responsibilities.
  6. Use the approved security contact for questions requiring private detail. This is a procurement and documentation checklist, not a completed security audit.

Example

An editor can prepare and revise documentation drafts, while publication remains an administrator action. Confirm comparable role boundaries for the client workspace before assigning approval, publishing or integration responsibilities.

If assurance material is missing

Request the specific policy or evidence. Do not replace it with a claim that the product is “enterprise-grade.” Independent certifications require current, relevant assurance material. Keep confidential architectural details and customer data out of public screenshots. Publish a clear summary of confirmed controls and provide an appropriate process for deeper review.