- Encryption: sensitive client data encrypted at rest with AES-256 and in transit with TLS 1.3.
- Authentication: unique accounts, strong password policy and MFA on administrative access; sessions time out on inactivity.
- Audit trail: security-relevant actions logged with actor, timestamp and context; logs retained 12+ months.
- Least privilege: production access restricted to named personnel; access reviewed quarterly and revoked on role change.
- Backups & recovery: encrypted backups with periodic restore testing.
- Vulnerability management: dependencies and platforms patched on a scheduled cycle; critical patches expedited.
- Incident response: documented response plan with containment, assessment, notification (72-hour standard) and post-incident review.
- Responsible disclosure: report suspected vulnerabilities to privacy@aesthetixspaces.com — we investigate all good-faith reports and do not pursue researchers acting responsibly.
© 2026 AesthetiX Spaces LLP. 55/3, 2nd Floor, RJ Complex, Sarjapura Main Rd, Yamare, Bengaluru, Karnataka 562125.
This document is part of the AesthetiX Legal Hub (v2.0, effective 17 July 2026) and is incorporated by reference into every estimate, quotation, invoice and Work Agreement. Questions: privacy@aesthetixspaces.com.

