Back to Trust Center

    Security Roadmap

    Last updated: August 1, 2026

    01Why We Publish This

    Most security pages list only what is finished. We publish the whole picture — shipped, in progress, and planned — so you can judge whether Astrixy fits your risk tolerance today rather than discovering a gap during procurement. Nothing on this page is a certification claim; items marked Planned are commitments of intent, not statements of current capability.

    This roadmap is reviewed and republished quarterly. Dates are deliberately omitted where we cannot commit to them honestly.

    02Status

    Shipped

    Row-level security across every tenant table

    Isolation enforced in the database engine rather than application filtering, covering all tenant-scoped tables including orders, products, customers, and payment records.

    Shipped

    Application-layer encryption for third-party credentials

    AES-256-GCM encryption for supplier API tokens, webhook signing secrets, and courier credentials before they are written to storage.

    Shipped

    Server-side entitlement and price enforcement

    Feature access and order totals are recomputed server-side from authoritative records; clients cannot set their own prices, totals, or payment status.

    Shipped

    Security scanning gate in CI

    Dependency, secret, and configuration scans run on every merge. Critical findings block deployment.

    Shipped

    Immutable audit logging

    Privileged operations, KYC decisions, payout changes, and administrative access are written to an append-only audit log retained for 12 months.

    Shipped

    Passkeys and TOTP two-factor authentication

    WebAuthn passkeys with biometric sign-in, TOTP authenticator support, session timeout, and individual session revocation.

    Shipped

    Production error monitoring with grouped alerting

    Server and client crashes are captured with source-mapped stack traces, deduplicated into issues with occurrence counts, and alerted on in real time.

    In progress

    Formalised incident response runbooks

    Documented severity definitions, on-call escalation, customer communication templates, and post-incident review process, with scheduled tabletop exercises.

    In progress

    Software bill of materials (SBOM)

    Automated CycloneDX generation on every release build, published to customers on request and diffed for new advisories.

    In progress

    Data residency controls

    Customer-selectable primary region for tenant data, with subprocessor routing aligned to the selected region.

    Planned

    Independent penetration test

    A third-party assessment of the dashboard, checkout, and API, with a summary letter shareable under NDA and remediation tracked publicly by severity.

    Planned

    SOC 2 Type I, then Type II

    Control mapping, evidence automation, and a readiness assessment, followed by a Type I audit and a subsequent Type II observation window.

    Planned

    ISO 27001 alignment

    Information security management system documentation and risk register, prioritised for European enterprise procurement.

    Planned

    Customer-managed encryption keys

    Bring-your-own-key support for enterprise tenants requiring control over the encryption key lifecycle.

    Planned

    Public bug bounty programme

    Monetary rewards on a published severity scale, launched once revenue supports a sustainable payout budget.

    03Influencing the Roadmap

    If a control on this page is a blocker for your organisation, tell us at security@astrixy.app. Customer demand is the primary input to prioritisation, and enterprise requirements have moved items forward before.

    Related: Trust Center, Security FAQ, Responsible Disclosure.