Infrastructure & Code Defense

Security Policy.

ZERO-TRUST INFRASTRUCTURE • CRYPTOGRAPHIC GOVERNANCE • REVISED: SEPTEMBER 2026

1. Zero-Trust Architecture Model

ZERO-TRUST

XPELAB builds software under the assumption that network perimeters are inherently compromised. No node, user, or microservice is trusted by default. Every API call, database mutation, and container request must be explicitly authenticated, authorized, and cryptographically verified before access is granted.

INGRESS PERIMETER
Mutual TLS (mTLS) v1.3
AUTHENTICATION
Hardware-Bound 2FA / FIDO2

2. Cryptography & Key Management

FIPS 140-2 LEVEL 3

We protect sensitive data across every stage of the transaction lifecycle using industry-standard, battle-tested cryptographic primitives:

  • In-Transit: TLS 1.3 enforced with forward secrecy and strict HSTS across all web gateways and internal microservices.
  • At-Rest: AES-256-GCM hardware-accelerated encryption across all databases, persistent volumes, and backups.
  • Key Enclaves: Master encryption keys and production signing secrets reside exclusively in Hardware Security Modules (AWS KMS / HashiCorp Vault Enclaves) with zero engineer root exposure.

3. Application Code Defense & CI/CD Testing

STATIC ANALYSIS

Code delivered through XPELAB adheres to our standardized Controller → Service → Repository patterns[cite: 1], eliminating ad-hoc queries and common attack vectors:

• SQLi & XSS Elimination: Parameterized queries, strict Eloquent ORM types, and output encoding.
• Automated Scans: Continuous SAST/DAST scanning, dependency vulnerability gates, and Psalm/PHPStan Level 8 checks on every commit.
• Tamper-Evident Logs: Write-once audit trails for every database mutation, login attempt, and privilege elevation[cite: 1].

4. Regulatory Frameworks & Compliance

CERTIFIED

Our architectures are built to pass strict third-party enterprise compliance audits across global operating verticals[cite: 1]:

PCI-DSS Level 1

Tokenized payment switches, zero-cardholder storage, and network isolation.

HIPAA & FHIR v4

End-to-end encrypted EHR interchanges and patient access governance.

SOC 2 Type II

Audited controls covering security, availability, and confidential handling.

ISO 27001:2022

Formal Information Security Management System (ISMS) implementation.

5. Incident Response SLA

24/7/365

XPELAB maintains dedicated SecOps coverage and contractually bound recovery parameters for enterprise managed tiers:

CRITICAL P1 RESPONSE
< 15 Minutes
RPO GUARANTEE
< 60 Seconds
RTO CUTOVER
< 5 Minutes

6. Responsible Vulnerability Disclosure

BUG BOUNTY

We welcome security researchers to test and review our public endpoints. If you discover a potential vulnerability, please notify our SecOps team responsibly without exploiting or degrading live services:

Security Inquiries: security@xpelab.com
PGP Key Fingerprint: 4A89 F012 3B4C D678 9E01 2345 6789 ABCD EF01 2345
Acknowledgment Window: Responses dispatched within 4 hours.
XPELAB Technical Copilot
Hello! I am XPELAB's AI Copilot. Ask me about our Enterprise modules, our XPELAB student prototypes, or launching an MVP sprint.