Skip to content
Trust

Security you can evidence, not just assert.

Datox handles data that is confidential, regulated and material. Security is treated as a design constraint on the platform rather than a layer added afterwards.

Controls

How data is protected

Access control

Role-based permissions govern who can see data, change reporting logic and approve outputs, with access reviewed as part of operation.

Encryption

Data is encrypted in transit and at rest, with key management handled by the platform infrastructure.

Segregation

Client data is logically segregated, and reporting environments are separated from development and testing.

Auditability

Every ingestion, transformation, validation, exception and approval is recorded with actor and timestamp.

Retention

Source evidence and produced outputs are retained according to configured retention requirements.

Operational practice

Change management, monitoring and incident handling govern how the platform is operated.

Due diligence

Support for your assessment process

Enterprise and regulated clients run formal vendor assessments. We support that process directly rather than pointing at a marketing page.

Available on request

  • Security documentation and architecture overview.
  • Data handling, hosting and retention details.
  • Access control and audit trail specifications.
  • AI usage documentation for governance review.
  • Responses to your standard vendor assessment questionnaire.
Independent assurance

SOC 2 Type II and ISO/IEC 27001

Datox maintains a SOC 2 Type II assurance report and ISO/IEC 27001 certification. SOC 2 Type II is an independent assurance report against the Trust Services Criteria, not a certification.

AICPA SOC seal

SOC 2 Type II

Independent assurance report

Independently assessed against the Trust Services Criteria for security, over an operating period rather than a single point in time. SOC 2 Type II is an assurance report, not a certification.

Report available to clients and prospects under NDA.

ISO 27001 certified badge

ISO/IEC 27001

Certified

A certified information security management system (ISMS) covering the Datox cloud platform and its supporting IT, security, HR, legal, administration and physical security functions.

Full certification scope and the certificate are shared with security and procurement teams.

ISMS scope

What the ISO/IEC 27001 certification covers

The Information Security Management System (ISMS) applies to the design, development, operation, maintenance and support of Datox's cloud-based SaaS platform for financial regulatory reporting and data automation, together with the supporting functions of IT and cloud infrastructure, information security, human resources, legal, administration and physical security, across the sites and legal entities included within the certification boundary.

  • In scope: the Datox cloud-based SaaS platform for financial regulatory reporting and data automation.
  • This scope statement describes the ISO/IEC 27001 certification only. It is not the scope of the SOC 2 Type II report, which is set out in the report itself.

Hosting regions, sub-processors and contractual commitments are confirmed in writing during procurement. The SOC 2 Type II report and the ISO/IEC 27001 certificate are shared with security and procurement teams on request.