Trust Center · Compliance

Sector readiness

Health, finance, public sector, legal, manufacturing — what AXOS enables and what stays with the customer.

Back to Trust Center

Source: docs/compliance/sector-readiness.md

Sector readiness — how AXOS enables customer compliance

Version 1.0
Review date 2026-08-21
Next review 2027-02-21

Framing rule. AXOS is not "HIPAA certified", "FCA approved", or "DSPT compliant". Those are properties of the customer organisation and its specific deployment. What AXOS does is enable a regulated customer to meet their own obligations, primarily by letting them run the platform inside their controlled boundary and by providing the controls listed below. Each section names what we provide, what we do not, and what stays with the customer.

Healthcare (NHS, private providers, life sciences)

Topic AXOS provides Not provided / customer
Data residency Self-hosted inside the trust or provider network; no content leaves Customer chooses region and hosting
NHS DSPT Controls that map to DSPT assertions (access control, audit, retention, encryption, incident handling) and the evidence to show them DSPT submission is the customer's
HIPAA (US) Platform can run inside a covered entity's HIPAA-aligned environment; no PHI reaches ScotiTech in self-hosted deployments ScotiTech is not a Business Associate for website/demo/standard support; a BAA is considered only for a specifically scoped engagement where we would handle PHI
Caldicott / IG ACL-first retrieval supports need-to-know; audit log supports Caldicott Guardian review IG policy and Guardian sign-off
Clinical decision use Not positioned for clinical decision support; AI output is administrative / knowledge-work assistance Any clinical use requires the customer's own clinical-safety case (DCB0129/0160) and MHRA assessment

Financial services (FCA / PRA regulated, insurers, asset managers)

Topic AXOS provides Not provided / customer
Operational resilience (SYSC 15A, PS21/3) HA reference topology, documented RTO/RPO pattern, customer-owned backups Important-business-service mapping and impact tolerances
Outsourcing / third-party risk (SYSC 8, SS2/21, DORA) Self-hosted minimises outsourcing scope; DPA, sub-processor list, audit clause, exit/deletion terms Register entry and due diligence
Record-keeping Per-request audit events exportable to SIEM Retention per COBS/MiFID as applicable
Consumer Duty / fair outcomes Human review gates and AI-output labelling Outcome testing on the customer's use case
Model risk (SS1/23) Model is customer-selected; connection logged; no training on customer data Model validation and governance

Public sector

Topic AXOS provides Not provided / customer
Data sovereignty Self-hosted; air-gapped pattern supported Accreditation under the body's own assurance scheme
Cyber Essentials CE self-assessment being completed now; CE Plus roadmap Supplier-assurance decision
Transparency (ATRS, FOI) Technical documentation pack; AI-output labelling Algorithmic Transparency Recording Standard entry
Equality Act / PSED Not evaluated by ScotiTech Equality impact assessment

Legal and professional services

Topic AXOS provides Not provided / customer
Confidentiality and privilege Data stays in the firm; ACL-first retrieval respects matter walls; PII-free logs Information barriers policy
SRA / Law Society guidance on AI AI-output labelling; human review gates; citations Supervision and competence obligations
Client consent Customer controls which matters are indexed Engagement-letter wording
Conflict checking Retrieval scoped by access, not a conflicts system Conflicts process remains the firm's

Manufacturing and critical infrastructure

Topic AXOS provides Not provided / customer
OT/IT separation Deployable on the IT side of the boundary; air-gapped option Segmentation and IEC 62443 zoning
NIS / NIS2 Supply-chain transparency (SBOM, sub-processors), incident handling commitments Competent-authority obligations
Quality systems (ISO 9001) Audit trail for document retrieval and AI-assisted drafts QMS integration

What every sector gets

  • Customer-controlled boundary; no content telemetry to ScotiTech; no training on customer data
  • Audit events exportable to the customer SIEM
  • Human review gates; per-workspace disable; AI-output labelling
  • Published retention schedule with automated enforcement
  • DPA, sub-processor list, DPIA support note, coordinated disclosure
  • Honest certification status (certification-roadmap.md)