Trust center overview

We build trust through inspectable responsibilities, explicit boundaries and version evidence rather than badges or broad promises. The items below describe the X·Neurons specification direction; released capability must be confirmed against the actual version, deployment and responsibility matrix.

Candidate status:This page is not a certification claim or a security guarantee for a specific project.

Data ownership and portability

Customers can obtain their own data, configuration and necessary evidence in understandable formats; exit must not create operational risk through technical lock-in. Core data export, contract termination and reasonable migration are basic rights — never hostage to proprietary formats or excessive export fees.

AI governance

AI output is candidate content, carrying sources, confidence and limitations; high-impact uses require human approval, permissions, sandboxing and rollback. Customer data must not be used to train shared models without an explicit contract. Generated content must not fabricate sources; when uncertain, the system should refuse or escalate to a person.

Governance principle:High-impact output must retain sources, limitations, authorization, human approval and a recovery path.

Deployment and data location

The product specification covers cloud, private, hybrid and edge deployment. Different deployments differ in capability and responsibility — we do not claim they are fully equivalent.

Identity and access

Direction: zero-trust and least privilege — people, services and devices each hold their own identity; encryption in transit and at rest; tamper-evident auditing of sensitive operations. Authorization is enforced server-side.

Safety boundary

X·Neurons does not presume to replace PLC, SIS, DCS or other safety-critical controllers. Any action touching safety controls remains governed by site procedures, permissions and certification.

Human review

Effective human review means the reviewer has the competence, sees the evidence, has enough time and holds a real right to refuse. Reasonable human overrides are a signal that human control works — not friction to eliminate.

Third-party services

Our principle is to keep the site free of external dependencies: every stylesheet, script, font and image is served by us, with no CDN, analytics tag or advertising platform. The one current exception is the locations map on the About Syno page. We list it here in full rather than burying it in general terms.

Third-party services currently in use

ServicePurposeData it receivesWhere it appears
Google Maps
Google LLC
Interactive map of the Taipei and Austin operating locations. Your IP address and browser information; Google may set its own cookies or local storage in your browser. The About Syno page only
Boundary:The Content Security Policy admits only the Google Maps hosts listed below and blocks every other external origin. The map receives nothing you type into forms on this site and is not joined to our traffic measurement, which is first-party and requires separate consent.

If your organization's policy forbids connections to Google, block the domain at the browser or network level — the two locations' addresses, phone numbers and service mailbox on the About Syno page stay fully readable without the map, and nothing else on the site is affected.

Certification status

No third-party certifications are currently listed as obtained. We do not imply non-existent certificates with badges; when certifications are obtained, they will be listed with scope, issuer and validity period.

Reporting a security issue

If you find a security issue, contact [email protected] with "Security" in the subject. Please do not include vulnerability details in the general contact form.