← Back to homeData Security Statement
EnezaXpress · Last updated: July 4, 2026
This page is maintained by EnezaXpress (operated by PAXTON BRANDS) to describe our current security posture. It is not an independent certification; certifications listed below refer to the vendors named.
Executive Summary
EnezaXpress implements enterprise-grade security measures to protect producer and buyer information. This statement outlines our technical safeguards, compliance framework, and commitment to data protection.
1. Infrastructure Security
1.1 Database & Storage
Platform: Supabase (PostgreSQL)
- Location: EU/US regional datacenters (configurable per compliance)
- Encryption: AES-256 encryption at rest
- Backup: Automated daily backups with 7-day retention
- Access Control: Role-based access; only system processes and authorized administrators access producer data
- Audit Logs: All database access is logged and monitored
1.2 Application Security
- HTTPS/SSL enforced on all connections
- Secure session management with token expiration
- CORS configured to prevent unauthorized access
- API authentication via JWT tokens
- Rate limiting to prevent abuse
- Input validation and sanitization on all endpoints
2. Data Protection in Transit
- TLS 1.3 encryption for all data transmissions
- HTTPS enforced on all endpoints
- Certificate pinning for API communications
- Secure channels for administrative access
3. Third-Party Security
We only integrate with vendors that meet strict security standards:
| Vendor | Purpose | Vendor Certification |
|---|
| Supabase | Database & Backend | SOC 2 Type II, ISO 27001 |
| Google Gemini API | AI Processing | ISO 27001, SOC 2 Type II |
| Resend | Email Delivery | SOC 2 Type II |
| Lemon Squeezy | Payment Processing | PCI DSS Level 1 |
All third parties commit via Data Processing Agreements to: GDPR compliance, restricted data use (no training, no resale), breach notification within 72 hours, and the right to audit security practices.
4. User Authentication & Access Control
- Multi-factor authentication available for producer accounts
- Strong password requirements enforced
- Automatic session logout after inactivity
- Admin access limited to core team; all actions logged
- Role-based permissions — producers see only their own data
5. AI & API Data Handling
5.1 Gemini API Usage
Data sent: Product/business descriptions, anonymized buyer research data, email draft templates.
Data NOT sent: Personal identifiers (names, emails), financial information, sensitive business secrets.
Gemini API does not use your data for model training and does not retain it beyond the operational window defined by Google.
5.2 Anonymization Process
- Producer names and personal emails are removed
- Business info is anonymized (e.g. "Uganda-based coffee exporter")
- Only processed insights are stored in your account
6. Compliance Framework
- Uganda Data Protection Act (2019) — consent, data minimization, right to deletion within 30 days
- GDPR (EU users) — legal basis for processing, DPIAs where required, compliant transfer mechanisms
- PCI DSS — payment data handled by Lemon Squeezy; EnezaXpress does not store card data
7. Incident Response
7.1 Breach Notification
- Affected users notified within 24 hours of confirmation
- Detailed breach report within 5 business days
- Remediation steps communicated
- Compliance with Uganda DPA and GDPR notification requirements
7.2 Security Monitoring
- Automated threat detection
- Regular security log reviews
- Periodic penetration testing
- Annual third-party security review
8. Producer Data Control
- Export data in standard formats (CSV, JSON)
- Delete data — full account deletion executed within 30 days
- Restrict processing — opt out of AI matching or email automation
- Transparency — view what data is collected and how it's used
9. Security Best Practices
Our team: annual security training, principle of least privilege, encrypted communication, background checks.
Development: secure coding (OWASP Top 10), code reviews, automated vulnerability scanning, staging tests before release.
10. Continuous Improvement
We regularly review security policies, monitor emerging threats, update encryption standards, and conduct security awareness training.
11. Contact
Security concerns: security@enezaxpress.com (response 24–48 hours).
Data Protection Officer: privacy@enezaxpress.com.
See also our Privacy Notice and Terms & Conditions.