Access control
Role-based permissions govern who can see data, change reporting logic and approve outputs, with access reviewed as part of operation.
Datox handles data that is confidential, regulated and material. Security is treated as a design constraint on the platform rather than a layer added afterwards.
Role-based permissions govern who can see data, change reporting logic and approve outputs, with access reviewed as part of operation.
Data is encrypted in transit and at rest, with key management handled by the platform infrastructure.
Client data is logically segregated, and reporting environments are separated from development and testing.
Every ingestion, transformation, validation, exception and approval is recorded with actor and timestamp.
Source evidence and produced outputs are retained according to configured retention requirements.
Change management, monitoring and incident handling govern how the platform is operated.
Enterprise and regulated clients run formal vendor assessments. We support that process directly rather than pointing at a marketing page.
Datox maintains a SOC 2 Type II assurance report and ISO/IEC 27001 certification. SOC 2 Type II is an independent assurance report against the Trust Services Criteria, not a certification.

SOC 2 Type II
Independent assurance report
Independently assessed against the Trust Services Criteria for security, over an operating period rather than a single point in time. SOC 2 Type II is an assurance report, not a certification.
Report available to clients and prospects under NDA.

ISO/IEC 27001
Certified
A certified information security management system (ISMS) covering the Datox cloud platform and its supporting IT, security, HR, legal, administration and physical security functions.
Full certification scope and the certificate are shared with security and procurement teams.
The Information Security Management System (ISMS) applies to the design, development, operation, maintenance and support of Datox's cloud-based SaaS platform for financial regulatory reporting and data automation, together with the supporting functions of IT and cloud infrastructure, information security, human resources, legal, administration and physical security, across the sites and legal entities included within the certification boundary.