Security, roles and data residency
XyReg is built for teams whose auditors ask hard questions about access control and data location.
Roles and permissions
Permissions are role-based and enforced server-side. Read-only auditor accounts can be issued for the duration of an audit and expire automatically.
Data residency
All customer data is stored on EU sovereign infrastructure (OVHcloud). No replication outside the EU, and a documented sub-processor list is available on request.
Security practices
- Encryption in transit (TLS 1.3) and at rest.
- ISO 27001 aligned information security management.
- Point-in-time backups with tested restore procedures.
- GDPR compliant processing with a standard DPA.
- SSO and enforced MFA available on Helix Workspace.
