Security
Architecture: less data, less risk
Wexolo's tools process files, audio, and documents entirely client-side, using WebAssembly, the Web Audio API, the Web Crypto API, and similar in-browser technology. That's a security decision as much as a privacy one: data that never reaches our servers can't be stolen from our servers. We can't leak, subpoena-comply with, or accidentally expose what we never had.
What does touch our servers
- Payment verification — handled server-to-server directly with PayPal's API. We never see your card or bank details.
- License tokens — signed with HMAC-SHA256 using a secret held only in server environment variables (never in client code, never in our git history). Verification uses constant-time comparison to resist timing attacks. Tokens carry a plan name and expiry — nothing else.
- Contact & support messages — submitted over HTTPS to our form handler.
Data residency
Our hosting provider serves this site from data centers in the United States. We don't currently offer a choice of processing region.
Access controls
Access to production environment variables (the license-signing secret, PayPal API credentials) is limited to the core engineering team, via our hosting provider's own access-control system.
Certifications & compliance
We don't hold formal third-party certifications (SOC 2, ISO 27001, HIPAA, etc.) yet — we're a new company and want to say so plainly rather than imply otherwise.
Penetration testing
No third-party penetration test has been performed yet. This page will be updated with the date and a summary once one has — we'd rather have an honest "not yet" here than a vague claim we can't back up.
Application-layer protections
- Content Security Policy restricting which domains can load scripts (only our own site and PayPal's official SDK) or open frames.
- Input sanitization on every form field and, notably, on uploaded SVGs before they're parsed or rendered.
- Server-side price enforcement — checkout amounts are looked up from a fixed price list on our server, never trusted from the browser.
- HTTPS/TLS everywhere, plus HSTS to prevent protocol downgrade attacks.
Reporting a vulnerability
If you find a security issue, please report it to support@wexolo.com before disclosing it publicly. Include steps to reproduce if you can.
Incident response & history
If we discover a security incident affecting user data, we'll investigate, contain it, and notify affected users and relevant authorities. A running log of past incidents lives on our status page.