Security and trust

Access should be deliberate, limited and reversible.

XERR uses layered technical controls and practical administration to reduce exposure, separate clients and preserve accountability.

01

Organisation boundaries

Licensed client workspaces are separated so one organisation cannot browse another client’s records.

02

Access by role

Administrators assign only the permissions needed for contributors, viewers, reviewers and project administrators.

03

Protected sign in

Passwords are stored using salted derivation and protected sessions expire automatically.

04

Scoped submission links

Upload only links expose one authorised submission route without exposing project dashboards or client administration.

05

Licence enforcement

Start dates, expiry, suspension and authorised user limits are checked centrally.

06

Traceability

Reviews, decisions, evidence and administrative actions retain an accountable history.

07

Hosted payment

Card details remain on the payment provider’s secure checkout and are not collected by the XERR website.

08

Rapid revocation

Client administrators can suspend users and links; XERR can suspend an organisation licence when required.

Data location

Software access and client evidence are separate things.

The public website stays lightweight because operational evidence is never used as marketing page content.

01

Public website

The XERR marketing website does not accept or store client project files, photographs, video, voice evidence or operational registers.

02

Hosted products

Where a product needs collaboration, structured records and large files are held in the product’s separate protected data services rather than inside the public website. Access is scoped to the licensed organisation.

03

Client side editions

IMS Gatekeeper, downloadable dashboards and standalone bespoke tools process their working information on the authorised user’s device or through an agreed client managed deployment. XERR does not silently copy XER content or working data into the marketing site.

04

Client owned storage

If a client requires its own Microsoft 365, cloud or enterprise storage boundary, that integration is agreed and configured during onboarding; it is never assumed or advertised before it exists.

Responsible security statement

No responsible provider can promise that a connected service is immune from every threat. XERR applies layered controls, least privilege access, secure development practices and rapid revocation, and continues to improve controls as the product family grows.

Security questions or suspected misuse should be reported to Support@xerr.co.uk.