Security & Encryption Policy
This Policy defines how Zenbitx LLC protects the confidentiality, integrity, and availability of data across its servers, including local infrastructure and AWS cloud deployment.
1. Purpose & Scope
This policy ensures the security of all user and operational data, defines encryption standards, and establishes safeguards for GDPR, CCPA, and industry compliance. It applies to:
- All Pixizen operational servers (Local and AWS Cloud).
- All user data processed through the platform.
- Internal and external communications containing sensitive information.
- System administrators, developers, and authorized personnel.
3. Data Classification
All data processed by Pixizen is classified into three tiers:
- Personal Data: PII, sensitive user content, and account information.
- Operational Data: Logs, metadata, and usage statistics.
- AI Training Data: Anonymized, consented data used for model refinement.
4. Encryption of Data at Rest
4.1 AWS Cloud Storage: Data on S3, RDS, and EBS is protected via AES-256 encryption. Access is restricted via IAM roles, and backup snapshots are encrypted.
4.2 Local Servers: Sensitive user data and operational logs are stored in AES-256 encrypted volumes. Encryption keys are managed via a secure KMS with strictly limited access.
5. Encryption in Transit & Key Control
- Transit: Communication between users, local servers, and AWS is secured via TLS 1.3 or higher. Internal APIs utilize mutual TLS (mTLS).
- Remote Access: SSH and RDP access is encrypted with public/private key authentication.
- Key Management: Keys are rotated at least every 12 months. We utilize AWS KMS and local Hardware Security Modules (HSM) or encrypted key stores.
7. Access Control & Recovery
We enforce Role-Based Access Control (RBAC) and require Multi-Factor Authentication (MFA) for all admin-level access. Encrypted backups are maintained on both AWS and local servers, tested regularly for integrity and restore capability to ensure minimum downtime.
9. Incident Response & Vendors
Monitoring: Continuous surveillance for malware and unauthorized access with automated alerts. In accordance with GDPR Article 33, breaches are notified within 72 hours.
Third Parties: All sub-processors (AWS, analytics) must comply with GDPR/CCPA security requirements via mandatory contractual encryption and breach notification clauses.
11. Personnel Responsibilities
Personnel must follow secure coding practices; plaintext storage of sensitive data is strictly prohibited. This policy is reviewed annually or upon significant infrastructure changes, supported by internal and third-party security assessments.
13. Legal & Compliance Standing
All measures meet GDPR Articles 25 & 32 and CCPA obligations. This framework ensures the confidentiality, integrity, and availability of data, supporting investor-grade SaaS compliance.