Security & Responsible Disclosure
CXTRUST combines controlled access, OTP authentication and operational safeguards with a clear route for reporting suspected security or privacy issues.
← Trust & Privacy CentreApplicant access uses registered identifiers and one-time verification controls.
Private evidence is separate from public verification information.
Suspected personal-data breaches are assessed against applicable notification requirements.
Security practices
- HTTPS and secure transport for public CXTRUST services.
- OTP-based applicant access and controlled administrative roles.
- Logging, backups and operational monitoring appropriate to the service.
- Separation between private assessment evidence and public verification.
- Payment processing through the configured payment provider rather than intentional storage of full payment-card details by CXTRUST.
Responsible disclosure
If you believe you found a security weakness, privacy issue or exposed CXTRUST information, email info@cxtrustmark.com with enough detail for us to investigate. Do not exploit the issue, access data that is not yours, disrupt the service, publish personal information or demand payment as a condition of disclosure.
Personal-data breach handling
CXTRUST assesses suspected incidents, contains and investigates them, records relevant facts and follows applicable notification obligations to regulators or affected individuals where required.