System Security Policy
Last updated: 2026-01-28
XSCORE is committed to protecting your data with enterprise-grade security measures. The system operates on Google Cloud Platform and FPT Smart Cloud infrastructure, complying with international security standards.
Security Overview
Multi-layered security system: • End-to-end encryption for sensitive data • Optional multi-factor authentication (2FA) • 24/7 security monitoring • Regular security audits and penetration testing • Dedicated security team Infrastructure: • Google Cloud Platform (GCP Singapore) • FPT Smart Cloud (Vietnam) • ISO/IEC 27001:2022 compliant
Data Encryption
Data in transit (encrypt-in-transit): • TLS 1.3/HTTPS for all connections • Certificate pinning for mobile apps • HSTS (HTTP Strict Transport Security) Data at rest (encrypt-at-rest): • AES-256-GCM encryption • Regular key rotation • Passwords hashed with bcrypt + salt Login passwords are additionally protected with end-to-end encryption.
Payment Security
PCI DSS compliant: • Tokenization - NO credit card numbers stored • 3D Secure 2.0 for international card transactions • Real-time fraud detection • Secure payment gateway (SePay, Polar) We do NOT store credit card information. All transactions are processed through PCI DSS certified payment gateways. VietQR: Payment via Vietnamese bank QR codes, processed directly by SePay.
Access Control
Least Privilege Principle: • Role-based Access Control (RBAC) • Single Sign-On (SSO) with Google, Apple ID • SAML 2.0 integration for enterprise • Secure session management with automatic timeout • IP whitelisting (optional for enterprise) • Complete audit log of all operations Account security features: • Two-factor authentication (2FA) with authenticator app • IP range access restrictions • New device login notifications
Monitoring and Logging
Continuous monitoring: • Security Information and Event Management (SIEM) • Intrusion Detection System (IDS) • DDoS protection (Cloudflare) • Regular vulnerability scanning • Quarterly penetration testing Logging: • Complete audit trail of all operations • Log retention per legal requirements • Automatic anomaly detection
Incident Response
Incident response process: 1. Detect and classify incident 2. Isolate and prevent spread 3. Investigate root cause and remediate 4. Notify customers (within 72h if data is affected) 5. Post-mortem and process improvement Commitment: Security incidents will be communicated as soon as possible and coordinated with authorities per legal requirements. 24/7 Security Hotline: +84 88 9615586
Report a Security Incident
Found a security vulnerability? Email: [email protected] Hotline: +84 88 9615586 Responsible Disclosure Program: • Valid security vulnerability reports will be acknowledged • No legal prosecution for good-faith researchers • Response time: 48 business hours Please do NOT disclose vulnerabilities before confirmed remediation.