Trust
Security & Compliance
Security is scoped into every engagement from the first estimate, not bolted on before launch.
Last updated: July 31, 2026
Data protection
All traffic is served over TLS with HSTS. Data at rest is encrypted by the managed platforms we deploy on. Access to production data follows least privilege, and every privileged action is logged.
Application hardening
We validate and sanitize every input on the server, enforce strict security headers and a content security policy, apply rate limiting to public endpoints, and protect forms against automated abuse.
File uploads
Uploads are restricted by type and size, stored outside the web root with non-guessable names, scanned for malware, and served only through short-lived signed links.
Responsible AI
AI features never act autonomously on client-facing output. Generation is triggered by a person, prompts and outputs are versioned and retained for audit, and AI assistance is disclosed to recipients. Provider abstraction means a vendor outage does not stop work.
Accessibility
We target WCAG 2.2 AA: semantic structure, keyboard operability, visible focus, contrast checks, and screen reader testing on interactive flows.
Reporting a vulnerability
Found something? Email hello@blexware.com with details and steps to reproduce. We acknowledge reports within two business days and will not pursue action against good-faith research.
