Security and data
Security & Data Protection
A hardware company's engineering information — what goes on each board, who it is bought from, why a revision changed — is sensitive business information. This page says what is done to protect it today, keeping two things apart that should not be mixed: this website, which exists and you can check, and the XKEMA application, which is not available yet.
Everything stated here describes what is running now. Nothing on this page is written in the future tense.
The website
Connection
- All traffic goes over HTTPS. An HTTP request is permanently redirected to HTTPS, and the browser receives an HSTS header telling it to come back over HTTPS without asking.
- The certificate is issued by Let's Encrypt and renews automatically.
- The site's cookies are marked secure — HTTPS only — and
SameSite=Lax; the visit-session cookie is alsoHttpOnly, so no script can read it.
Browser headers
The site declares a content security policy that limits where each resource may load from, forbids the page from being shown inside someone else's frame, stops the browser from guessing file types, and trims what is sent as a referrer when you leave for another site.
Forms
- Everything submitted through a form is validated on the server. Browser-side validation is convenience, not control.
- Forms are protected against cross-site request forgery (CSRF).
- Every public form has an invisible field that a person never fills in: if it arrives filled, the submission is discarded silently.
- There is an hourly submission limit for contact, waitlist, demo booking and panel sign-in.
- The three public forms use Google reCAPTCHA v3, which scores each submission without asking you to solve anything. If the check cannot be made, the submission is rejected: when in doubt, it does not go through.
What this website collects
- Contact form
- What you type: name, email, company and the message. Nothing else.
- Waitlist
- The email address only. The public sign-up asks for nothing else.
- Demo booking
- What is needed to meet: name, email, company, role and, if you want to say, what you would like to solve.
- Usage measurement
- If you allow it, which pages are viewed and how you arrived. The next section explains it in full.
The legal detail — retention periods, lawful basis and your rights — is in the privacy policy and in the cookies policy.
Usage measurement, in detail
This website does not use Google Analytics, Tag Manager, advertising pixels or any third-party analytics platform. Measurement is first-party: this site's own code writing to this site's own database.
- Your IP address is not stored. There is no field to store it in.
- Your location is not derived, and no profile is built from it.
- If your browser sends «Do Not Track» or «Sec-GPC», or if you decline in the cookie banner, your browsing is not recorded. Neither is the browsing of anyone signed in to the internal panel.
- Requests that look automated are discarded before sessions are counted. All that remains of them is a daily number per reason — how many were filtered and why — with no path, no session and no identifier: no individual visit can be reconstructed from that tally.
- Para contar una visita como una y no como cinco se usa un valor aleatorio en una cookie propia, que caduca a los 30 minutos sin navegar y no identifica a nadie.
- When measurement is allowed, the site also records the approximate time a page stayed visible in your browser. It measures visibility, not reading or attention, it is sent once when you leave the page, and it adds no cookie.
- Las visitas se borran a los 400 días, y lo hace un trabajo programado, no una buena intención.
Third-party services
Two, and this is what they do:
- Google reCAPTCHA v3
- Tells a person from a script on the contact, waitlist and demo booking forms. The browser loads it and it may use its own storage.
- Mailgun
- Delivers the email the site generates — a demo confirmation, the notice of a new message — through its European Union infrastructure.
There is no other external service: no fonts, icons, videos or maps loaded from elsewhere.
The XKEMA application
The XKEMA application is not publicly available yet.
That is why you will not find a list of application security controls here: encryption at rest, permissions, expiry of shared links. Publishing them now would describe a system nobody can use yet, and you would have no way to check it.
The application's security documentation will be published at the same time as public access, so that what it says matches the system actually in use.
Certifications
XKEMA holds no security certification today — no ISO 27001, no SOC 2, none. It is said here because the absence of a list of badges is often read as them being held but not shown.
Found a security issue?
Tell me and I will look into it. There is no bounty programme and no special form: write, and I answer personally.
info@xkema.com Or use the contact form