Security Overview
Effective 11 October 2026 · Last updated 11 October 2026
1. Identity and access controls
The portal is designed around individual accounts, verified business email, authenticator-app multi-factor authentication, role-based membership and tenant-scoped data access. Signup invitations are email-bound, expire after seven days and are stored as token digests; redemption is designed as a single atomic operation. Exado administrators should grant access only to trusted staff and review access regularly. Users should keep passwords and authenticator factors private and report lost devices promptly.
2. Data separation and activity
Customer, partner and internal workspaces are represented as separate tenants. Application access is intended to be enforced by Firestore Security Rules, and workspace changes are recorded in activity entries where supported. The preview’s data model and rules may evolve; customers should not treat tenant separation as a substitute for their own security review or a signed production commitment.
3. Transport, hosting and providers
Exado uses Google Firebase hosting, authentication and Cloud Firestore for the current portal. Firebase services deliver traffic over HTTPS and apply their infrastructure security controls. Firestore data is configured in the European multi-region `eur3`; other Firebase services may process data under Google’s service architecture. See the Privacy Notice for provider and transfer details. Exado will publish material additional subprocessors and integration providers as production features are introduced.
4. AI and connected systems
The current preview is not connected to Microsoft, Jira or other customer systems, and Mangi is not wired to a live AI model or external tools. When those features are launched, Exado intends to request scoped permissions, explain what will be read or changed, present a reviewable plan, and require an authorized person’s approval before an external write action. Customers should review each requested scope and action and should not assume that an advertised future control is active until the product identifies it as enabled.
5. Incident response
Exado will assess reported security concerns, take reasonable containment and remediation steps, and notify customers, affected people or authorities when required by applicable law or contract. To report a suspected incident, write to info@exado.app. Do not send passwords, recovery codes, MFA codes, access tokens or customer records.
6. Responsible vulnerability disclosure
Report security findings privately to info@exado.app. Include a summary, affected endpoint and reproducible steps. Make a good-faith effort to avoid accessing, changing or deleting other people’s data; do not disrupt the service, perform social engineering, or publish exploit details before coordinating remediation. Exado will acknowledge reports as operational capacity permits. This is not a bug-bounty program and does not grant permission to test systems that you do not own.
7. Customer responsibilities
Customers must choose suitable data, configure least-privilege access, keep their users informed, protect their own endpoints and credentials, review approvals and maintain any required external backups. Until Exado confirms production readiness and the parties sign suitable terms, use only synthetic or low-risk preview information.
8. Updates and contact
We will update this page as controls and product features change. Security contact: info@exado.app.