Effective Date: July 28, 2026 • Enterprise Data Security Policy
ExoTech collects business intake details (name, corporate email, project scope, budget selection) submitted through our client portal and intake forms. Technical metadata such as IP address, browser user-agent, and session tokens are captured for system health audit trails and multi-tenant security verification.
All customer data is encrypted in transit via TLS 1.3 and at rest using AES-256 GCM encryption. Integrations and API credentials are stored securely with zero plain-text storage. Client Portal records strictly follow Attribute-Based Access Control (ABAC) to enforce isolated data boundaries between organizations.
We do not sell, rent, or monetize your corporate data. Data is shared exclusively with vetted provider abstractions (such as payment gateways, AI model endpoints, and email delivery networks) required to deliver contractually agreed engineering services.
For data access requests, deletion, or privacy inquiries, contact our Privacy Compliance Office at privacy@exo-tech.org.