Security Operations — All Systems Nominal

XDC Gateway Trust Center

We take security seriously. This Trust Center provides transparent access to our security practices, compliance status, infrastructure design, and audit reports — everything you need to confidently build on XDC Gateway.

99.99%
Uptime SLA
SOC2
Type II Prep
TLS 1.3
Encryption
100%
Audit Logs
Section 01

Security Overview

Our defense-in-depth strategy combines encryption, access controls, monitoring, and continuous testing to protect your data and infrastructure.

Overall Security PostureStrong
7 of 8 controls fully implemented87%

Data Encryption

Active

All data in transit encrypted with TLS 1.3. Data at rest uses AES-256 encryption across all storage tiers including database backups.

Access Management

Active

Role-based access control (RBAC) with MFA enforced for all admin accounts. API keys are hashed using SHA-256 before storage.

Audit Logging

Active

Comprehensive audit trails for all administrative actions, API access, and configuration changes. Logs retained 365 days.

Intrusion Detection

Active

Real-time anomaly detection via Fail2Ban and custom rate-limiting rules. Automated IP blocking on suspicious patterns.

Vulnerability Management

Active

Weekly automated dependency scans via npm audit and Dependabot. Critical patches applied within 24 hours of disclosure.

Network Segmentation

Active

Private VPC with strict inbound/outbound firewall rules. Database and internal services isolated from public internet.

DDoS Mitigation

Active

Cloudflare-backed DDoS protection with automatic traffic scrubbing. Rate limiting enforced at both edge and application layers.

Security Testing

In Progress

Annual third-party penetration tests. Internal red-team exercises quarterly. Bug bounty program in planning.

Responsible Disclosure Policy

If you discover a security vulnerability, please report it to security@xdcrpc.com. We commit to acknowledging reports within 48 hours and providing regular updates. We do not pursue legal action against researchers acting in good faith.

Section 02

Compliance Status

We continuously work toward industry-standard certifications and compliance frameworks. Download available reports and assessments below.

ISO/IEC 27001

Information Security Management System

Gap Assessment Complete

Gap assessment completed March 2026. Formal certification audit scheduled Q3 2026. 78% of controls implemented.

Implementation Progress78%
Download Gap Assessment

SOC 2 Type II

Trust Services Criteria

In Preparation

SOC 2 readiness assessment underway. Targeting Type I audit Q2 2026 and Type II completion Q4 2026.

Implementation Progress45%

GDPR

General Data Protection Regulation

Compliant

Data Processing Agreements available for enterprise customers. No PII stored outside EU-compliant infrastructure. Privacy policy updated Jan 2026.

Implementation Progress95%

Penetration Testing

Third-Party Security Assessment

Completed

Full-scope penetration test completed by independent security firm. Scope covers web app, API, network, and smart contracts.

Implementation Progress100%
Download Pentest Scope

Policy Registry

Last audited: March 2026
Information Security Policy
Jan 2026Request
Data Retention Policy
Jan 2026Request
Incident Response Procedure
Feb 2026Request
Change Management Policy
Mar 2026Request
Acceptable Use Policy
Jan 2026Request
Vendor Risk Management
Feb 2026Request
Section 03

Infrastructure

Built for reliability and scale. Our multi-region infrastructure ensures low latency, automatic failover, and zero single points of failure.

Regional Availability

All regions operational
US East (Virginia)
Primary
< 12ms
CPU Load68%
EU West (Frankfurt)
Active
< 18ms
CPU Load44%
Asia Pacific (Singapore)
Active
< 22ms
CPU Load51%
US West (Oregon)
Standby
< 15ms
CPU Load12%

Technology Stack

Edge & CDN
Cloudflare

Global anycast routing, DDoS protection, WAF, SSL termination across 200+ PoPs

Load Balancer
Nginx + eRPC

Health-aware load balancing across 4 eRPC instances. Automatic failover < 100ms

Compute
Bare Metal Linux

Ubuntu 22.04 LTS on dedicated hardware. No hypervisor overhead. PM2 process management

Data Layer
PostgreSQL + Redis

PostgreSQL 16 with daily encrypted backups. Redis for session/rate-limit caching with AOF persistence

RPC Nodes
XDC + EVM Nodes

Dedicated full nodes for XDC Mainnet & Apothem. Peered with 15+ additional EVM networks

Secret Management
Environment Vaults

Secrets stored in encrypted environment files. No hardcoded credentials. Rotation every 90 days

Service Level Agreements

MetricTargetCurrentStatus
API Availability99.99%99.97%Met
P50 Response Time< 50ms32msMet
P99 Response Time< 500ms218msMet
Incident Response< 15 min8 min avgMet
Data Recovery (RTO)< 4 hours< 2 hoursMet
Section 04

Transparency

We believe in open communication about incidents, security updates, and our sub-processor relationships. Here's what we share publicly.

99.97%
90-Day Uptime
3
Incidents (90d)
44 min
Avg Resolution

Incident Log

Mar 15, 2026Minor 42 min

Elevated RPC Latency — US East

Identified memory pressure on eRPC-0 node. Increased heap limit and restarted process. No data loss.

Resolved
Feb 28, 2026Minor 18 min

Rate Limit Misconfiguration

Configuration push incorrectly lowered rate limits for enterprise tier. Rolled back and re-deployed correct config.

Resolved
Feb 10, 2026Moderate 1h 12min

Database Connection Pool Exhaustion

Surge in dashboard traffic exhausted PostgreSQL connection pool. Scaled pool size and added PgBouncer connection pooler.

Resolved

Security & Compliance Changelog

Mar 2026
Security
Migrated to TLS 1.3 exclusively

Removed TLS 1.2 support across all endpoints. Improved cipher suite configuration.

Feb 2026
Compliance
ISO 27001 Gap Assessment completed

Third-party consultant completed full gap assessment. Remediation roadmap published internally.

Feb 2026
Infrastructure
Added EU West (Frankfurt) region

New regional node reduces latency for European users by 40%. Automatic geo-routing enabled.

Jan 2026
Security
MFA enforced for all admin accounts

TOTP-based MFA now mandatory for all users with admin or billing roles.

Jan 2026
Compliance
Privacy policy updated for GDPR alignment

Data retention schedules, processor agreements, and right-to-erasure flows updated.

Sub-processor Registry

ProviderPurposeRegionCertification
CloudflareCDN, DDoS, WAFGlobalSOC2 Type II
Hetzner CloudCompute InfrastructureEU / USISO 27001
PostmarkTransactional EmailUSSOC2 Type II
TelegramOps NotificationsGlobalPrivacy Shield
Section 05

Contact & Resources

Reach the right team directly. We're committed to transparent communication and rapid response on all security and compliance matters.

Security Issues

security@xdcrpc.com

Report vulnerabilities, suspected breaches, or security concerns. We follow responsible disclosure. Acknowledge within 48h.

Response: < 48 hours

Compliance & Legal

legal@xdcrpc.com

Data Processing Agreements, GDPR requests, compliance documentation, sub-processor questions.

Response: 2–3 business days

General Trust Inquiries

trust@xdcrpc.com

Questions about our security program, policy documents, or to request a security questionnaire review.

Response: 1–2 business days

Enterprise Support

enterprise@xdcrpc.com

Dedicated account management, custom SLAs, white-label agreements, and enterprise security reviews.

Response: Same business day

Ready to build with confidence?

Start with our free tier — 100K requests/month. Upgrade to enterprise for dedicated SLAs, custom compliance documentation, and 24/7 support.