Trust & security
Last updated 5 September 2026. This page is the public trust summary for researchers, enterprise security reviews, and banking / procurement questionnaires.
If you find a vulnerability in xelta.ai, the public REST API, MCP (mcp.xelta.ai), or a related Xelta service, email us before publishing it.
Include the affected host or product, a short impact description, and enough detail for us to reproduce. Do not include customer data, credentials, or exploit payloads in the first message. We acknowledge reports and do not pursue legal action against good-faith researchers who follow this process.
Public traffic for xelta.ai, api.xelta.ai, mcp.xelta.ai, and media.xelta.ai is served over HTTPS and sits behind Cloudflare (CDN, TLS, and WAF). Application APIs run on AWS. Generation endpoints and the MCP server require authentication; unauthenticated calls to /mcp are rejected.
Xelta does not currently publish a completed SOC 2 Type I/II or ISO/IEC 27001 certificate. We are aligning operational controls to the SOC 2 Trust Services Criteria (security, availability, confidentiality) so an independent attestation can be completed. Until that report is issued we will not display a SOC 2 or ISO badge.
Enterprise and banking teams can request a security questionnaire (SIG, CAIQ, or custom) at [email protected]. Underlying cloud providers (AWS, Cloudflare) maintain their own SOC 2 / ISO attestations for the infrastructure we use.
How we collect and process account, billing, and uploaded media data is described in the Privacy Policy. Product terms are in Terms & Conditions.