Por ahora, esta página solo está disponible en inglés.
Security
Last updated: September 2026 · Version: 1.0 · Controller / Processor: TriStiX S.L.
1. Policy Statement
Security is a first-class product property at NetSenX, not an afterthought. We commit to:
- Store customer data in the EU, encrypted at rest and protected by TLS 1.3 in transit; where a provider outside the EU is involved, the transfer safeguards are listed in the Data Processing Agreement.
- Operate the platform under a documented incident-response procedure with a 72-hour breach-notification SLA to controllers and supervisory authorities (GDPR Art. 33).
- Welcome good-faith security research and never pursue legal action for in-scope, in-good faith disclosures (see Responsible Disclosure).
- Publish a machine-readable security contact under /.well-known/security.txt per RFC 9116.
2. Security Controls Summary
| Area | Control |
|---|---|
| Encryption at rest | AES-256 (EU database provider) |
| Encryption in transit | TLS 1.3 only; HSTS preload enabled |
| Key management | Encryption keys managed by the EU database provider |
| Data residency | Customer database in Ireland (AWS eu-west-1); API in Frankfurt and Paris; dashboard hosted in the EU. The website is served from Cloudflare’s global network. |
| Audit trail | Tamper-evident SHA-256 hash chain for every administrative action |
| Access control | RBAC (Admin / Analyst / Viewer / Auditor); MFA mandatory for Admin role |
| Vulnerability management | SAST, dependency scanning, supply-chain signing; 72h patch SLA for critical CVEs |
| Backups | Daily automated, 30-day retention, EU region, encrypted at rest |
| Limited protocol inspection | The agent works mainly from flow metadata and reads only a few protocol fields on the monitored host (TLS server name, DNS answers, industrial control commands). It never decrypts encrypted connections, and in its standard configuration no packet content is sent. Server names are sent only in a random sample of about 1 in 1,000 flow records. |
3. Vulnerability Disclosure
We operate a Coordinated Vulnerability Disclosure (CVD) programme. For full details including scope, safe harbor, SLA, and disclosure timelines, see Responsible Disclosure.
Researchers can locate our security contacts at any time via the RFC 9116 file at /.well-known/security.txt.
4. Bug Bounty
NetSenX’s bug-bounty programme is hosted on Intigriti and is in setup ahead of V1b. The programme will open to invited researchers first, then to the public, with bounty bands commensurate with severity (CVSS v4.0). In the interim, please use the email channel described below; valid in-scope reports submitted during the soft-launch phase will be eligible for retroactive bounty consideration.
5. Sensitive Reports
We do not publish a PGP key at present. If your report contains working exploit code or sensitive data, send a short first message to [email protected] without those details, and we will reply to agree how to receive them.
6. Incident Response
- Detection: 24×7 alerting on platform-wide health and security telemetry.
- Containment: a documented runbook covers credential rotation, tenant isolation review, and forensic preservation.
- Notification: affected customers are notified within 24 hours of confirmed breach (DPA Section 9); regulatory authorities within 72 hours (GDPR Art. 33).
- Post-incident: root-cause analysis is published privately to the affected customers within 14 days, with remediation timelines.
7. Compliance & Certifications
See /compliance for the current status of our compliance roadmap (NIS2, GDPR, ISO 27001, SOC 2 Type II).
8. Contact
- Security reports: [email protected]
- Machine-readable contact: /.well-known/security.txt
- Coordinated Disclosure policy: /responsible-disclosure