Security

Last updated: September 2026

Reporting a vulnerability

If you believe you have found a security vulnerability in the excede platform or in www.excede.ai, report it to privacy@excede.ai. You do not need an existing relationship with us to report one.

Please include enough detail to reproduce the issue: the affected URL or endpoint, the steps you took, and what you observed. If you have a proof of concept, include it. We will acknowledge your report and tell you what we intend to do about it.

Reports enter the same triage process as findings from our own scanning and testing. The Engineering Lead triages within two business days of receipt.

If you are researching in good faith

We will not pursue legal action against you for security research conducted in good faith under the guidance below, and we will treat your report as an authorised contribution rather than an intrusion.

  • Test only against accounts and data you own or have explicit permission to use.
  • Stop as soon as you have established that a vulnerability exists. Do not read, copy, modify or delete customer data, and do not pivot further into our systems.
  • Do not degrade the service. No denial of service, no load testing, no spam.
  • Do not use social engineering, phishing, or physical attacks against our people or our vendors.
  • Give us a reasonable opportunity to remediate before disclosing publicly. We will tell you when the fix has shipped, and we are happy to credit you.

We do not currently operate a paid bug bounty. That is not a comment on the value of your report.

Remediation timeframes

Vulnerabilities are classified by CVSS severity and remediated within the following targets, measured from triage. Where a target cannot be met, we record a documented risk acceptance with the compensating controls in place and a revised date.

SeverityCVSSRemediation target
Critical9.0 – 10.07 calendar days
High7.0 – 8.930 calendar days
Medium4.0 – 6.990 calendar days
Low0.1 – 3.9Next scheduled maintenance, or formally risk-accepted

How the platform is protected

  • Tenant isolation enforced at the database layer through row-level security, covered by automated tests that run against the migration history on every change.
  • Encryption — AES-256 at rest, TLS 1.2 or higher in transit. Integration credentials are additionally encrypted at the application layer with a key rotated at least every 90 days.
  • Authentication — multi-factor authentication is available to all accounts and enforceable per organization. Passwords are screened against a breach corpus and stored only as salted hashes; we never see them.
  • Automated security testing on every change — static analysis, software composition analysis of all dependencies, and secret scanning. A change cannot merge with any of these failing.
  • Backups — two independent encrypted tiers held with different providers, daily snapshots retained 7 days and weekly full backups retained 28 days.
  • Audit logging — authorization events, access to customer data and administrative actions are recorded and attributable to an identified individual.

Compliance

We are pursuing SOC 2 Type II certification. Our practices are aligned with the SOC 2 Trust Services Criteria and with ISO 27001 principles. We maintain a documented information security policy set, a risk register, and a published sub-processor list.

Our contractual security commitments to customers are set out in the Data Security Addendum. How we handle personal information is described in our Privacy Policy.

Contact

Security and privacy at Excede are owned by a single accountable role, the Security & Privacy Officer, reachable at privacy@excede.ai. That address is monitored for vulnerability reports, privacy requests and data protection enquiries.

Excede, Inc. · 1654 Calle Tulipan, Suite 100, San Juan, Puerto Rico 00927-6242