Security Policy
The safeguards protecting your data — and how to report a vulnerability.
Last updated: 7 July 2026 · Effective: 7 July 2026
Ownership. Xtallo is a product owned and operated by XDQ Labs Private Limited, a company incorporated under the Companies Act, 2013 (India). All intellectual property in the Xtallo platform and this website belongs to XDQ Labs Private Limited. For legal notices, write to info@xdqlabs.com.
On this page
1. Our approach
Security is foundational to a trust platform. We design for least privilege, defence in depth, and rapid response, and review our practices continuously.
2. Data protection
- Data encrypted in transit (TLS 1.2+) and at rest.
- Passwords stored using strong one-way hashing; never in plaintext.
- Verification evidence handled with restricted, need-to-know internal access.
3. Access & operations
- Role-based access control and mandatory MFA for internal systems.
- Audit logging of administrative actions.
- Vendor due diligence for providers that process user data.
4. Incident response
We maintain an incident response process covering detection, containment, remediation, and notification. Where a breach affects your personal data, we notify you and the relevant authorities (including the Data Protection Board of India, where applicable) as required by law.
5. Responsible disclosure
If you believe you’ve found a vulnerability, report it privately to info@xdqlabs.com with steps to reproduce. Please don’t access other users’ data, disrupt the service, or disclose publicly before we’ve had a reasonable chance to remediate. We acknowledge reports within 3 business days and won’t pursue action against good-faith research within these rules.
6. Your part
Use a strong, unique password, keep your email secure, and report anything suspicious to hello@xtallo.com.