Trust and security

Security at xFusion.

When you bring xFusion into your business, you are giving us access to customer conversations, helpdesk data, and internal tools. We treat that access like the responsibility it is. Here is how.

Last updated: April 29, 2026
The shape of the problem

What our security model actually has to protect.

We are a managed customer support service. Most of the data we touch lives in tools our clients already own (Help Scout, Intercom, Zendesk, Gorgias, Front, HubSpot, Shopify, etc.). We work inside those tools as authorized users with role-based permissions. That structure is intentional, because it means data stays where the client already has security and audit controls in place.

The places where xFusion holds data directly are narrower: payroll for our placed team, internal documentation about each client's workflows, our recruiting pipeline, and the operational tooling we use to run the business. Each layer below describes how we protect those.

People

Who has access, and how we keep it that way.

Hiring and vetting

Every team member goes through the TraitX framework before placement. That includes background screening appropriate to the role and jurisdiction, identity verification, reference checks, and a structured assessment of judgment and discretion under pressure. Less than one percent of applicants make it through.

Confidentiality and training

  • Every team member signs a confidentiality and IP agreement before they receive any client access.
  • Onboarding includes security training: phishing recognition, credential hygiene, customer data handling, and reporting suspicious activity.
  • Refresher training runs at least annually and after any incident or material policy change.
  • Account managers reinforce security expectations during weekly one-on-ones with placed team members.

Access lifecycle

  • Access is provisioned per client, per tool, with the minimum permissions needed for the role.
  • Multi-factor authentication is required on every system that holds client or company data.
  • When a team member rolls off an account or leaves xFusion, access is revoked the same business day, with documented confirmation.
  • Account managers review access lists on a recurring cadence and remove anything stale.
Systems and infrastructure

How the technical layer is set up.

  • TLS 1.2 or higher in transit; data at rest is encrypted on the cloud platforms we rely on.
  • Company-managed devices for the operations and account management teams, with disk encryption and endpoint protection enforced by policy.
  • Password manager with strong, unique credentials per system; shared accounts avoided as a rule.
  • Centralized logging and audit trails wherever the underlying tool supports them.
  • Vulnerability management: dependencies and platforms are patched promptly; critical issues are prioritized.
  • Network controls: production tooling sits behind authentication; sensitive admin functions are restricted to a small group.
  • Backups for company-owned systems run on a schedule appropriate to the data, with periodic restore checks.
Data handling

What we do, and do not, do with client data.

  • We process client data only to deliver the services in the agreement: respond to support tickets, run the helpdesk, manage the team, report on KPIs.
  • We do not sell client data and do not use it to train external AI models.
  • AI tools used in client workflows are scoped to the client's own environment and configured according to the client's instructions.
  • Client data is returned or deleted at the end of the engagement, on request.
  • For data we are the controller of (billing contacts, candidate information), retention follows our Privacy Policy.
Vendors and Sub-processors

The third parties we rely on.

We use established platforms for hosting, communication, payroll, helpdesk operations, and analytics. We choose vendors with mature security practices and review them periodically. A current list of named Sub-processors is available on request and is also referenced in our Data Processing Addendum.

Incident response

If something goes wrong.

  • Documented incident response process owned by xFusion leadership.
  • Suspected incidents are triaged immediately; impact and scope are confirmed before broader action.
  • Affected clients are notified without undue delay, with the facts we know and the steps we are taking.
  • Post-incident review captures root cause, remediation, and the durable change so it does not happen again.
Compliance and documentation

What we will provide on request.

  • Data Processing Addendum for clients with GDPR, UK GDPR, or CCPA / CPRA obligations.
  • Standard Contractual Clauses where required for international transfers.
  • Sub-processor list and notification of material changes.
  • Security questionnaire responses for client procurement teams.
  • NDA before any sensitive technical or operational details are shared.

xFusion does not currently hold a SOC 2 attestation. We are happy to walk through our controls in detail and to share documentation against any framework you are aligning to internally.

Reporting a concern

Talk to us.

If you believe you have found a vulnerability, observed suspicious activity involving xFusion, or have a security question, contact security@xfusion.io. We typically respond within one business day. Please do not include sensitive personal data in your initial message; we will set up a secure channel as needed.

For broader privacy questions, see our Privacy Policy or email info@xfusion.io.