Skip to content

Trust

Security & Compliance

Security is scoped into every engagement from the first estimate, not bolted on before launch.

Last updated: July 31, 2026

Data protection

All traffic is served over TLS with HSTS. Data at rest is encrypted by the managed platforms we deploy on. Access to production data follows least privilege, and every privileged action is logged.

Application hardening

We validate and sanitize every input on the server, enforce strict security headers and a content security policy, apply rate limiting to public endpoints, and protect forms against automated abuse.

File uploads

Uploads are restricted by type and size, stored outside the web root with non-guessable names, scanned for malware, and served only through short-lived signed links.

Responsible AI

AI features never act autonomously on client-facing output. Generation is triggered by a person, prompts and outputs are versioned and retained for audit, and AI assistance is disclosed to recipients. Provider abstraction means a vendor outage does not stop work.

Accessibility

We target WCAG 2.2 AA: semantic structure, keyboard operability, visible focus, contrast checks, and screen reader testing on interactive flows.

Reporting a vulnerability

Found something? Email hello@blexware.com with details and steps to reproduce. We acknowledge reports within two business days and will not pursue action against good-faith research.