Data Security Statement
Last Updated: June 5, 2026
Xuzhou Mangxu Software Technology Co., Ltd. is committed to protecting your data security. This document describes the security measures we implement, where data is stored, and our security incident emergency response mechanism. It has been developed in accordance with the Data Security Law of the People's Republic of China and the Cybersecurity Law of the People's Republic of China.
1. Security Management System
1.1 Organizational Structure
- A designated Data Security Officer oversees all data security management activities
- Comprehensive data security management policies and operating procedures are established
- Regular data security awareness training is provided to all employees
- A data security performance assessment and accountability mechanism is in place
1.2 Data Classification and Grading
We manage all processed data under a classification and grading system (pursuant to Article 21 of the Data Security Law):
| Data Level | Description | Protection Measures |
|---|---|---|
| Public Data | Product introductions, company information, etc. | Basic protection |
| Internal Data | Business statistics, operational data | Access control + log auditing |
| Sensitive Data | User personal information, transaction data | Encrypted storage + masked display + strict access permissions |
| Core Data | Encryption keys, system configurations | Highest-level encryption + physical isolation + dual-person operation |
2. Technical Security Measures
- Transport Security: Full-site HTTPS (TLS 1.2/1.3), API communications secured with HMAC signature authentication
- Storage Security: Database encryption at rest (AES-256), sensitive fields encrypted independently
- Access Control: Four-level RBAC permission system, least privilege principle, operation audit logging
- Network Security: Firewalls, WAF, DDoS protection, intrusion detection system
- Application Security: Input validation, SQL injection protection, XSS protection, CSRF tokens
- AI Security: Prompt injection protection, output content filtering, model access permission controls
3. Data Backup and Recovery
- Automated full database backup daily, retained for 30 days
- Incremental backups performed every 6 hours
- Backup data encrypted and stored at an off-site disaster recovery center
- Quarterly backup recovery drills conducted
- RPO (Recovery Point Objective) ≤ 6 hours, RTO (Recovery Time Objective) ≤ 4 hours
4. Data Storage Location
All user data is stored in data centers located within the People's Republic of China. No cross-border data transfer occurs. Servers are deployed in facilities certified under the Multi-Level Protection Scheme (MLPS).
5. Security Incident Response
In accordance with Article 25 of the Cybersecurity Law and Article 57 of the Personal Information Protection Law (PIPL), we have established a security incident emergency response mechanism:
- Detection Phase (0–1 hour): Security monitoring systems trigger automated alerts; the security team confirms the incident severity level
- Containment Phase (1–4 hours): Affected systems are isolated to prevent further damage
- Notification Phase (24–72 hours): Affected users and regulatory authorities are notified
- Recovery Phase (within 72 hours): Systems are repaired and services restored
- Review Phase (within 7 days): An incident analysis report is produced and protective measures are enhanced
6. Security Audit and Assessment
- At least one external security assessment conducted annually
- Regular penetration testing and vulnerability scanning
- Security impact assessments performed prior to critical system changes