Sector readiness — how AXOS enables customer compliance
| Version | 1.0 |
| Review date | 2026-08-21 |
| Next review | 2027-02-21 |
Framing rule. AXOS is not "HIPAA certified", "FCA approved", or "DSPT compliant". Those are properties of the customer organisation and its specific deployment. What AXOS does is enable a regulated customer to meet their own obligations, primarily by letting them run the platform inside their controlled boundary and by providing the controls listed below. Each section names what we provide, what we do not, and what stays with the customer.
Healthcare (NHS, private providers, life sciences)
| Topic | AXOS provides | Not provided / customer |
|---|---|---|
| Data residency | Self-hosted inside the trust or provider network; no content leaves | Customer chooses region and hosting |
| NHS DSPT | Controls that map to DSPT assertions (access control, audit, retention, encryption, incident handling) and the evidence to show them | DSPT submission is the customer's |
| HIPAA (US) | Platform can run inside a covered entity's HIPAA-aligned environment; no PHI reaches ScotiTech in self-hosted deployments | ScotiTech is not a Business Associate for website/demo/standard support; a BAA is considered only for a specifically scoped engagement where we would handle PHI |
| Caldicott / IG | ACL-first retrieval supports need-to-know; audit log supports Caldicott Guardian review | IG policy and Guardian sign-off |
| Clinical decision use | Not positioned for clinical decision support; AI output is administrative / knowledge-work assistance | Any clinical use requires the customer's own clinical-safety case (DCB0129/0160) and MHRA assessment |
Financial services (FCA / PRA regulated, insurers, asset managers)
| Topic | AXOS provides | Not provided / customer |
|---|---|---|
| Operational resilience (SYSC 15A, PS21/3) | HA reference topology, documented RTO/RPO pattern, customer-owned backups | Important-business-service mapping and impact tolerances |
| Outsourcing / third-party risk (SYSC 8, SS2/21, DORA) | Self-hosted minimises outsourcing scope; DPA, sub-processor list, audit clause, exit/deletion terms | Register entry and due diligence |
| Record-keeping | Per-request audit events exportable to SIEM | Retention per COBS/MiFID as applicable |
| Consumer Duty / fair outcomes | Human review gates and AI-output labelling | Outcome testing on the customer's use case |
| Model risk (SS1/23) | Model is customer-selected; connection logged; no training on customer data | Model validation and governance |
Public sector
| Topic | AXOS provides | Not provided / customer |
|---|---|---|
| Data sovereignty | Self-hosted; air-gapped pattern supported | Accreditation under the body's own assurance scheme |
| Cyber Essentials | CE self-assessment being completed now; CE Plus roadmap | Supplier-assurance decision |
| Transparency (ATRS, FOI) | Technical documentation pack; AI-output labelling | Algorithmic Transparency Recording Standard entry |
| Equality Act / PSED | Not evaluated by ScotiTech | Equality impact assessment |
Legal and professional services
| Topic | AXOS provides | Not provided / customer |
|---|---|---|
| Confidentiality and privilege | Data stays in the firm; ACL-first retrieval respects matter walls; PII-free logs | Information barriers policy |
| SRA / Law Society guidance on AI | AI-output labelling; human review gates; citations | Supervision and competence obligations |
| Client consent | Customer controls which matters are indexed | Engagement-letter wording |
| Conflict checking | Retrieval scoped by access, not a conflicts system | Conflicts process remains the firm's |
Manufacturing and critical infrastructure
| Topic | AXOS provides | Not provided / customer |
|---|---|---|
| OT/IT separation | Deployable on the IT side of the boundary; air-gapped option | Segmentation and IEC 62443 zoning |
| NIS / NIS2 | Supply-chain transparency (SBOM, sub-processors), incident handling commitments | Competent-authority obligations |
| Quality systems (ISO 9001) | Audit trail for document retrieval and AI-assisted drafts | QMS integration |
What every sector gets
- Customer-controlled boundary; no content telemetry to ScotiTech; no training on customer data
- Audit events exportable to the customer SIEM
- Human review gates; per-workspace disable; AI-output labelling
- Published retention schedule with automated enforcement
- DPA, sub-processor list, DPIA support note, coordinated disclosure
- Honest certification status (certification-roadmap.md)
