Security Statement

Last Updated: December 21st, 2025
Legal Entity: Seraphex Inc (registered in Macomb County, Michigan, United States)
Security Contact:[email protected]
General Support:[email protected]

1. Purpose

This Security Statement describes Seraphex Inc’s approach to protecting customer data and maintaining the security and integrity of Seraphex products and services. This statement is provided for informational purposes and does not modify or replace any contractual terms. In the event of any conflict, the Terms of Service and Privacy Policy govern.

2. Security Program Overview

Seraphex applies administrative, technical, and organizational safeguards designed to protect the confidentiality, integrity, and availability of the Services. Security is treated as an operational priority, and safeguards are continuously reviewed and improved over time.

3. Infrastructure and Hosting

The Services are hosted in cloud-based infrastructure with physical and environmental protections consistent with modern data center standards. Seraphex uses controlled network boundaries and system isolation practices intended to reduce risk and limit unauthorized access.

4. Data Protection

4.1 Encryption in Transit

The Services use industry-standard encryption in transit (for example, TLS/HTTPS) to protect data exchanged between customer devices and Seraphex systems.

4.2 Encryption at Rest

Seraphex uses encryption and access controls designed to protect stored customer data against unauthorized access. Specific technical implementations may evolve as systems are improved.

5. Access Controls and Authentication

Seraphex limits access to systems and customer data based on role and business need. Administrative access is restricted to authorized personnel. Customers are responsible for maintaining appropriate access controls within their organizations and for safeguarding account credentials.

6. Logging, Monitoring, and Auditability

The Services generate operational and security logs to support system monitoring, troubleshooting, and investigation of suspected abuse or security incidents. Where applicable, customer-facing logs and audit trails may be available within the product to support internal accountability and oversight.

7. Vulnerability Management

Seraphex works to identify, prioritize, and remediate security vulnerabilities in a timely manner. Security updates may be deployed without advance notice where necessary to protect the Services and customers.

8. Incident Response

Seraphex maintains an incident response process designed to investigate, contain, and remediate security incidents. If Seraphex confirms a security incident that materially impacts customer data, Seraphex will provide notice to affected customers as required by applicable law and consistent with contractual commitments.

9. Third-Party Service Providers

Seraphex may use third-party service providers to support delivery of the Services (for example, hosting, communications, security tooling, and payment processing). Seraphex evaluates providers as appropriate and seeks to maintain safeguards and contractual protections consistent with the provider’s role.

10. Customer Responsibilities

Customers are responsible for using the Services in a secure manner. This includes maintaining strong passwords, restricting account access to authorized users, configuring permissions appropriately, and promptly notifying Seraphex of suspected unauthorized access or security issues.

11. Responsible Disclosure

If you believe you have discovered a security vulnerability affecting the Services, please report it to [email protected]. Please do not publicly disclose potential vulnerabilities until Seraphex has had a reasonable opportunity to investigate and address the report.

12. Questions

For questions regarding this Security Statement, contact [email protected].