Last updated: August 9, 2026
Security is foundational to ESXPress. This page documents our security architecture, encryption practices, compliance posture, and responsible disclosure policy — written for enterprise IT teams, security auditors, and procurement reviewers evaluating our platform. If you have questions that aren't answered here, contact us at [email protected].
max-age=31536000 directive, including includeSubDomains.Retry-After header. Authenticated users have higher per-account limits based on subscription tier.ESXPress has implemented the Trust Services Criteria (TSC) Common Criteria 6 (CC6) controls from the AICPA SOC 2 framework. These controls address logical and physical access, system operations, change management, and risk mitigation:
Note: ESXPress is actively pursuing a formal SOC 2 Type II attestation. The CC6 controls listed above are implemented and operating. Contact [email protected] for our most recent self-assessment and auditor readiness status.
Checking MFA status…
ESXPress maintains a documented incident response plan covering identification, containment, eradication, recovery, and post-incident review. In the event of a confirmed security incident affecting customer data, affected customers will be notified within 72 hours of confirmation, in compliance with GDPR Article 33 notification requirements.
No security program can guarantee absolute protection. We do not guarantee that the Service will be immune to all attacks, vulnerabilities, or unauthorized access, and we are not liable for losses caused by attacks on third-party infrastructure or by your failure to follow security practices (for example, safeguarding your credentials). Likewise, this page describes our security posture — it is not a warranty that any specific security measure will prevent every incident, and it does not guarantee the accuracy of AI-generated output (see our AI Disclosure and Terms of Service).
We take the security of ESXPress seriously. If you discover a security vulnerability, we encourage you to report it through our responsible disclosure program. We value the contributions of the security research community and are committed to working with you to verify, reproduce, and remediate legitimate findings.
This disclosure policy applies to the ESXPress web application (esxpress.org), our REST API, and any subdomains under esxpress.org. Third-party services used by ESXPress (Stripe, Supabase, Cloudflare) maintain their own disclosure programs.
For enterprise procurement teams, security questionnaires, or custom security requirements: