Private by default
Documents live in a private vault, encrypted in transit and at rest by our infrastructure providers.
Trust & security
X1 protects the documents behind your financial picture, limits access to the people you authorize, and keeps supported AI work tied to sources you can inspect.
Documents live in a private vault, encrypted in transit and at rest by our infrastructure providers.
Household and professional access is scoped to current relationships and explicit sharing grants, which can be revoked.
On supported document-grounded workflows, X1 presents source citations so you can verify the answer.
We record key document access and sharing events to support accountability, security review, and incident response.
Current posture
Claims reviewed
Before anything leaves your household
Limited authorized X1 personnel and subprocessors may process data when needed to operate and secure the service. Household and professional access remains scoped to current relationships and explicit sharing grants.
Before approval, the household can see what will be prepared, who is expected to receive it, and what happens next.
Nothing is sent until the household approves the material and the intended recipient.
The handoff, response, and confirmed outcome remain connected to the sources that produced the work.
AI you can interrogate
X1 uses commercial API services—not personal chatbot accounts—for production processing. We do not grant model providers permission to train on household content; exact contractual coverage and retention are verified route by route.
Your data choices
Access, export, correction, login removal, content deletion, and verified erasure are related choices—but they are not the same operation. X1 explains the scope and consequence of each.
Review your privacy rightsCompliance status
X1 is operating a readiness program focused on Security and Confidentiality, with Privacy controls being prepared in parallel. We do not currently hold or claim a SOC 2 report or certification.
For firms and advisers
We can discuss our security architecture, data flow, access model, subprocessor posture, AI use, deletion controls, and current evidence status under NDA.
Start security diligenceA question we have not answered?
We will share what we can plainly, including where a control depends on an infrastructure provider or remains in progress.