Human Capital CXO
Legal & Trust — SEC-RSS-001
Security Statement
Effective: 2026-06-01  •  Version 1.2  •  Review cycle: Annual

1. Our Security Approach

HumanCapital CXO® applies defence-in-depth security across all layers of the HCV Model platform. This statement describes the technical and organisational measures in place as of the effective date above. We update this page when material changes are made.

2. Infrastructure Security

LayerProviderMeasures
Network edgeCloudflareDDoS mitigation, WAF (Web Application Firewall), bot management, TLS 1.3 everywhere, HSTS enforced, no HTTP allowed
Access controlCloudflare WorkersEvery request to /* validated against a Supabase JWT before the origin server is reached. Invalid or expired tokens are rejected at the edge — the origin never sees unauthenticated requests.
DatabaseSupabase (PostgreSQL)AES-256 encryption at rest; Row Level Security (RLS) — every user can only read/write their own rows; no direct database internet exposure
AuthenticationSupabase Authbcrypt-hashed passwords; short-lived JWT session tokens; secure HttpOnly cookies; PKCE where applicable
Origin hostingCloudflare Pages / static hostingNo server-side code at origin for static HTML pages; attack surface minimised

3. Data Protection Measures

4. Access Controls

5. Monitoring and Incident Response

6. Vulnerability Disclosure

If you discover a security vulnerability in the platform, please report it responsibly to security@humancapitalcxo.com. Include a description of the issue, steps to reproduce, and your contact details. We will acknowledge receipt within 48 hours and aim to resolve confirmed vulnerabilities within 90 days. We will not take legal action against good-faith security researchers who follow this process.

Please do not publicly disclose the issue until we have had a reasonable opportunity to address it.

7. Third-Party Security Posture

8. Penetration Testing and Audits

We conduct annual security reviews of authentication flows, access control logic, and data handling. Enterprise customers may request a copy of our most recent security assessment summary under NDA by contacting security@humancapitalcxo.com.

9. Contact

Security enquiries: security@humancapitalcxo.com
General privacy: privacy@humancapitalcxo.com