Trust centre
Everything Xovris can fix, and every control you keep
What Xovris can fix, how deep it goes and how every repair is proven – with every control you keep.
What Xovris did on customers' systems
From launchCounted from the audit record of every change, across all workspaces together, so no customer can be picked out.
The live record of what Xovris’s AI does opens at launch, with every figure counted from real work.
Xovris right now
Xovris’s live status opens at launch, measured by its own probes from the first day.
How deep Xovris goes
From the page your visitors see down to the networks and devices behind it. Each layer shows what Xovris fixes there and whether it is ready today.
Websites and pages
AvailablePages that fail, slow down or go offline – found from outside, fixed and proven for every visitor.
See it workingDomains and DNS
BetaChanged or tampered records put back to their last verified version, with expiry and renewal watched.
See it workingEmail and sender trust
AvailableWho sends email as you, and the exact records that stop anyone else from doing it.
See it workingApps and code
BetaErrors traced to the release that caused them, and the fix delivered as a change you review.
See it workingSecurity
BetaCertificates, DNSSEC and tampering caught early and put right.
See it workingCloud accounts
PlannedWho changed what in your cloud, and a risky setting put right.
Networks
PlannedOffice and home networks watched, and a fault traced to the device behind it.
Devices
PlannedThe laptops, phones and machines a business or a family relies on, kept healthy.
Every repair is tested before and after – and guaranteed
A fix counts only when it is proven. Until then you pay nothing for it.
Reproduced first
Your own failing outcome is reproduced before anything changes.
Fixed within what you allow
Only the access you granted, with every step recorded.
Proven after
Re-run after the fix with the checks around it, and confirmed by a verifier separate from the fixer.
Paid when it passes
You pay nothing for a fix until its after-test passes.
If an after-test fails, the change is put back exactly as it was and the next approach starts. The issue stays open and visibly progressing until a fix is proven.
The only limits: law, safety and consent
Xovris goes as deep as your systems go. These three are the only things that stop it, and each is named when it applies.
Law
Xovris acts only on systems you own or are allowed to manage, and where the law says a person must decide, a person decides.
Safety
A change that could harm people, data or money waits for a person – and anything that does not hold is put back.
Consent
Nothing changes without the access you granted, and you can take that access back at any time.
What each connection lets Xovris fix
Each provider in turn: the fixes it unlocks first, then the exact access its own consent screen asks for and how to take it back – read access shown apart from change.
GitHub
What it lets Xovris fix
- To commit the setup change to a new branch. Nothing is ever pushed to your default branch.
- To open one pull request whose description lists every change.
The exact access, and how to take it back
Can read
- See repository names – To let you pick the one repository the setup change goes into.
- Read files in chosen repositories – To read the package manifests and the files that start your app - nothing else.
- Read check results on that pull request – To tell you whether your own checks passed on the setup change.
Can change
- Commit to a setup branch in chosen repositories – To commit the setup change to a new branch. Nothing is ever pushed to your default branch.
- Open the setup pull request – To open one pull request whose description lists every change.
To take it back: Uninstall the Xovris GitHub App from the repository; closing the pull request also deletes its branch.
Vercel
What it lets Xovris fix
- To write the Xovris variables into the projects you choose, then read them back.
- To keep the integration resource Vercel shows you in step with Xovris.
The exact access, and how to take it back
Can read
- See your projects and deployments – To map each deployment to its environment and release.
Can change
- Write environment variables – To write the Xovris variables into the projects you choose, then read them back.
- Manage the Xovris resource Vercel holds – To keep the integration resource Vercel shows you in step with Xovris.
To take it back: Uninstall the integration in Vercel: Xovris deletes only the variables it added, revokes every key it issued and reads both back.
Cloudflare DNS
What it lets Xovris fix
- Only if you allow repairs: to put a changed record back to its last verified version under your standing policy.
The exact access, and how to take it back
Can read
- See your zones and their settings – To find the zone you chose and confirm its name servers.
- Read DNS records – To keep every verified version of your records, so a change can be explained and undone.
Can change
- Change DNS records – Only if you allow repairs: to put a changed record back to its last verified version under your standing policy.
To take it back: Revoke the Xovris grant in your Cloudflare profile; Xovris notices the revocation and stops offering repairs.
Slack
What it lets Xovris fix
- To post alerts and their updates in the channel you choose.
The exact access, and how to take it back
Can read
- See public channel names – To let you pick a channel by name.
- See private channels the app is in – To let you pick a private channel the app was invited to.
- See who people are, to mention the right person – To mention the person who owns the alert.
- Match members by email address – To match your Xovris members to their Slack accounts.
Can change
- Post alerts in channels the app is in – To post alerts and their updates in the channel you choose.
To take it back: Remove the Xovris app from your Slack workspace; Xovris reads the revocation and falls back to email.
Connections not listed here – the SDKs, OpenTelemetry and the coding-agent server – send data to Xovris and get no access to your systems at all.
Certifications
Xovris holds no certification yet. Each is listed with its true status, and gains its date and its evidence the day it is earned – never before.
SOC 2 Type II
Not held
An independent audit of security controls over a period of months.
ISO/IEC 27001
Not held
The international standard for an information security management system.
ISO/IEC 42001
Not held
The international standard for managing AI systems responsibly.
Your data, and the AI
Where your data lives
Your data lives in the EU (Netherlands and Germany) site, chosen when you sign up.
- Your account, checks, incidents and changes: the Netherlands
- Error events and check results: the Netherlands
- The history of each repair while it runs: Germany
Your data stays in the site you choose. Moving it later means exporting it and importing it into another site.
Sub-processors
None yet. Xovris processes no customer data until it opens, and every sub-processor that will handle your data, and where, is listed here before it does.
AI governance
- Your data never trains anyone else’s AI. Xovris learns from fixes only after names, addresses, secrets and content are removed, and only as your settings allow. Xovris only uses providers whose terms forbid training on customer content.
- A person approves every change unless you set a standing policy for that kind of change.
- Anything written by Xovris is labelled as written by Xovris.
- Nothing from one workspace is ever visible to another – the database itself enforces it.
Report a vulnerability
Write to [email protected] with “Security” in the subject. Please do not test against other customers' data or degrade the service.
If it is being exploited now, put “Exploited” in the subject as well. Those reports are handled first, and an actively exploited vulnerability in Xovris is reported to ENISA within 24 hours, with an update within 72 hours and a final report, as the Cyber Resilience Act requires.
- What you found and where
- How to reproduce it, step by step
- What an attacker could do with it
Accessibility
Xovris is built to WCAG 2.2 level AA.
Not yet independently audited; the result will be published here with its date.