Trust Center

Everything an enterprise buyer needs to review AXOS

The AXOS Trust Center collects certifications, security posture, privacy artefacts, and the evidence pack in one place. Anything not published here can be requested under NDA as part of the procurement pack.

Compliance status

Certifications and alignment

Last reviewed: August 2026

Aligned

UK & EU GDPR

General Data Protection Regulation

Customer data does not leave the customer-controlled boundary in production. Data Processing Agreement, subprocessor list, and privacy policy are published on this site.

Implemented

TLS 1.3 · AES-256 · RBAC

Baseline security controls

Modern transport security for public traffic, industry-standard encryption at rest with customer-managed keys, and role-based access control across administrative and user surfaces.

In progress

ISO 27001

ISO/IEC 27001:2022

Information security management system work is underway. Progress statement, controls mapping, and target certification date available under NDA on request.

In progress

SOC 2 Type II

SOC 2 Trust Services Criteria

SOC 2 Type II readiness work is in progress. Timeline and independent auditor selection available under NDA. In the meantime, the trust artefacts on this page are the equivalent evidence we share with reviewers.

In progress

Cyber Essentials Plus

UK NCSC Cyber Essentials Plus

Cyber Essentials Plus certification work is on the ScotiTech roadmap. Progress and target date available under NDA on request.

AXOS is not currently certified to ISO 27001, SOC 2 Type II, or Cyber Essentials Plus. We work with an honest posture: certification work is in progress, and the trust artefacts on this page — plus the evidence pack released under NDA — are what we share with security reviewers today.

Evidence pack (under NDA)

The full evidence pack is released after a short procurement conversation and a signed NDA. Contents map line-for-line to the questions asked in a typical enterprise security review.

Request the procurement pack
  • ISO 27001 progress statement and controls mapping
  • SOC 2 Type II readiness statement
  • Cyber Essentials Plus target roadmap
  • Data Processing Agreement (DPA)
  • Subprocessor list with processing regions
  • SBOM and signed checksum references per release
  • Security responses to SIG-Lite and CAIQ
  • Penetration test summary letter
  • Insurance certificates
  • ICO registration reference

Talk to us

Security teams, procurement, and legal all have a direct route in. We aim to acknowledge every incoming trust or procurement request within two business days.

Procurement and commercial
info@scotitech.com
Operator
ScotiTech Solutions Limited · Companies House SC829021