Neweb / Security

Security, by default.

Your customers trust you with their data. We treat yours the same way — encrypted in transit and at rest, with role-based access and regular audits across every Commerciax product.

01

Encryption Everywhere

Every connection to Neweb uses TLS 1.3. Every database and storage bucket is encrypted at rest with AES-256. Backups are encrypted independently with separate keys.

No plaintext customer data lives on any disk, ever.
02

Access Controls

We enforce role-based access controls. Every engineer action on production is logged and reviewed. Access requires single sign-on with hardware-key 2FA. Production access is scoped to the minimum needed for the task and audited weekly.

03

Backups & Recovery

  • Hourly incremental backups.
  • Daily full backups.
  • Weekly off-site replicas, encrypted with separate keys.
  • Point-in-time restore available to any customer on request within 30 days.
04

Monitoring & Audits

We run continuous vulnerability scanning, automated dependency audits, and third-party penetration tests annually. All critical findings have SLAs on resolution time.

05

Compliance

  • Aligned with GDPR, CCPA, and India's DPDP Act (2023).
  • SOC 2 Type II audit in progress (target: Q3 2026).
  • ISO 27001 roadmap in planning.
06

AI & Data Confidentiality

We do not use client data to train public models.

AI-generated outputs from Neweb remain scoped to your account and content. Model providers are bound by data-processing agreements that prohibit training on customer inputs.

07

Responsible Disclosure

Found a vulnerability? Email info@commerciax.com with [SECURITY] in the subject and full reproduction steps. We respond within 48 hours, acknowledge valid findings, and offer a bounty for severe issues. Please don't disclose publicly until we've had a reasonable window to fix.

08

Contact