UK & EU GDPR
General Data Protection Regulation
Customer data does not leave the customer-controlled boundary in production. Data Processing Agreement, subprocessor list, and privacy policy are published on this site.
Trust Center
The AXOS Trust Center collects certifications, security posture, privacy artefacts, and the evidence pack in one place. Anything not published here can be requested under NDA as part of the procurement pack.
Compliance status
Last reviewed: August 2026
General Data Protection Regulation
Customer data does not leave the customer-controlled boundary in production. Data Processing Agreement, subprocessor list, and privacy policy are published on this site.
Baseline security controls
Modern transport security for public traffic, industry-standard encryption at rest with customer-managed keys, and role-based access control across administrative and user surfaces.
ISO/IEC 27001:2022
Information security management system work is underway. Progress statement, controls mapping, and target certification date available under NDA on request.
SOC 2 Trust Services Criteria
SOC 2 Type II readiness work is in progress. Timeline and independent auditor selection available under NDA. In the meantime, the trust artefacts on this page are the equivalent evidence we share with reviewers.
UK NCSC Cyber Essentials Plus
Cyber Essentials Plus certification work is on the ScotiTech roadmap. Progress and target date available under NDA on request.
AXOS is not currently certified to ISO 27001, SOC 2 Type II, or Cyber Essentials Plus. We work with an honest posture: certification work is in progress, and the trust artefacts on this page — plus the evidence pack released under NDA — are what we share with security reviewers today.
Published artefacts
Every artefact below is reachable without authentication. Send the links to your internal reviewers.
Deployment posture, encryption, access control, audit logging, and the coordinated vulnerability disclosure policy.
Open
How ScotiTech processes personal data across the AXOS website, hosted demo, and procurement conversations.
Open
The terms that govern access to the AXOS website and hosted demo. Customer-deployed AXOS is covered by the master engagement contract.
Open
What is and is not allowed on the AXOS marketing site and hosted demo environment.
Open
Named subprocessors that support AXOS-operated services, with processing location and data category.
Open
Company entity, Companies House registration, contract routes, and procurement pack request.
Open
The full evidence pack is released after a short procurement conversation and a signed NDA. Contents map line-for-line to the questions asked in a typical enterprise security review.
Request the procurement packSecurity teams, procurement, and legal all have a direct route in. We aim to acknowledge every incoming trust or procurement request within two business days.