Security

No system — including this one — can honestly promise to be unhackable or crash-proof. What we can tell you is exactly what we built and why, so you can judge the risk yourself.

Architecture: less data, less risk

Wexolo's tools process files, audio, and documents entirely client-side, using WebAssembly, the Web Audio API, the Web Crypto API, and similar in-browser technology. That's a security decision as much as a privacy one: data that never reaches our servers can't be stolen from our servers. We can't leak, subpoena-comply with, or accidentally expose what we never had.

What does touch our servers

Data residency

Our hosting provider serves this site from data centers in the United States. We don't currently offer a choice of processing region.

Access controls

Access to production environment variables (the license-signing secret, PayPal API credentials) is limited to the core engineering team, via our hosting provider's own access-control system.

Certifications & compliance

We don't hold formal third-party certifications (SOC 2, ISO 27001, HIPAA, etc.) yet — we're a new company and want to say so plainly rather than imply otherwise.

Penetration testing

No third-party penetration test has been performed yet. This page will be updated with the date and a summary once one has — we'd rather have an honest "not yet" here than a vague claim we can't back up.

Application-layer protections

Reporting a vulnerability

If you find a security issue, please report it to support@wexolo.com before disclosing it publicly. Include steps to reproduce if you can.

Incident response & history

If we discover a security incident affecting user data, we'll investigate, contain it, and notify affected users and relevant authorities. A running log of past incidents lives on our status page.