Skip to content
Platform

Built for data you cannot afford to get wrong.

Reporting data is sensitive: positions, investors, financial results and regulatory submissions. Datox is designed around access control, evidence and oversight, including oversight of the AI components themselves.

Independent assurance

SOC 2 Type II and ISO/IEC 27001

Datox's security posture is independently assessed. Reports and certification scope are shared directly with your security and procurement teams during evaluation.

AICPA SOC seal

SOC 2 Type II

Independent assurance report

Independently assessed against the Trust Services Criteria for security, over an operating period rather than a single point in time. SOC 2 Type II is an assurance report, not a certification.

Report available to clients and prospects under NDA.

ISO 27001 certified badge

ISO/IEC 27001

Certified

A certified information security management system (ISMS) covering the Datox cloud platform and its supporting IT, security, HR, legal, administration and physical security functions.

Full certification scope and the certificate are shared with security and procurement teams.

Controls

Governance across the reporting workflow

Access control

Permissions by role and scope determine who can see source data, change logic, resolve exceptions and release output.

Auditability

Runs, changes, exceptions, comments and approvals are recorded chronologically against the reporting period.

Evidence retention

Source inputs and extraction references are retained so outputs remain defensible after the fact.

Segregation of duties

Preparation, review and approval can be separated and enforced through permissions.

Change control

Mapping and validation logic is versioned, so historical periods stay reproducible.

AI oversight

Agent actions are logged with inputs and evidence; low-confidence output is escalated to a person.

AI governance

How AI is constrained inside the platform.

Datox uses AI to remove repetitive work, not to make unreviewable judgements. Deterministic calculations and validations remain deterministic, and agent output that affects a reported figure is evidenced and reviewable.

Principles applied

  • Agents show the source evidence behind extracted or suggested values.
  • Confidence thresholds decide what requires human review.
  • Pass/fail validation logic is rule-based, not model-based.
  • Human approval remains the final step before a report is released.
  • Agent activity forms part of the same audit trail as human activity.
Deployment

SaaS, private or on-premise

Datox can be deployed to match your security, data-residency and internal policy requirements. The available options and their scope are confirmed during procurement.

SaaS

Datox-managed hosting for teams that want the fastest route to a running reporting workflow.

Private deployment

A dedicated environment for organisations with stricter isolation or data-residency requirements.

On-premise

Deployment inside your own infrastructure where internal policy requires data to remain there, subject to scope and requirements.

Certification status, hosting region, data residency and retention terms are confirmed in writing during procurement. Please treat any specific security claim as subject to confirmation with the Datox team.