xmodoxmodo

Customers

Organisations that run their compliance on xmodo

Organisations in banking, government, healthcare, information technology and e-commerce use xmodo to meet the regulations and standards that apply to them. We do not publish customer names.

Our customers

Sectors we serve

Our customers work in these sectors. Each answers to more than one regulator or standard.

  • Banking

    Banks answer to their central bank, the card schemes and data protection authorities at the same time, and examiners expect evidence that controls worked throughout the period under review. xmodo holds each regulation's requirements, owners and evidence in one place. When an incident is classified, the regulator's reporting deadlines start on the incident record.

  • Government

    Government entities follow national information assurance standards, and often the rules of an emirate or sector authority as well. Audits come from more than one direction. xmodo sets up each standard under its official title and edition, and links every audit finding to the corrective action that closes it.

  • Healthcare

    Health regulators expect patient information to be protected across every hospital, clinic and system. xmodo runs the regulatory, privacy and security programme on one set of controls, so each control is implemented once and counts towards every standard that requires it.

  • Information technology

    Technology companies that sell to large enterprises receive security questionnaires and audit requests from customers in many countries, alongside their own SOC 2 and ISO 27001 audits. xmodo keeps one set of evidence for their certifications and drafts answers to customer questionnaires from the same record.

  • E-commerce

    Online retailers take card payments and hold personal data about large numbers of customers. They must meet PCI DSS and the data protection laws of each market they sell into. xmodo collects evidence from their cloud and payment systems through integrations, and raises a renewal task before any item expires.

In common

What xmodo changes for them

The sectors differ, but the work is the same: several frameworks, evidence that must stay current, and decisions that an examiner can review.

One set of controls

Each control is implemented once and counts towards every framework it satisfies. Adding a framework shows how much of it existing controls already cover.

Evidence that stays current

Evidence has an owner and an expiry date. A renewal task is raised before anything lapses, so auditors do not find out-of-date evidence first.

AI with recorded approval

The AI drafts mappings, policies and questionnaire answers. A named person approves each one, and the audit trail records the decision.

References

Speak to a customer

We arrange customer references under NDA. Ask for one when you get a demo, and we will try to introduce you to a customer in a sector close to yours.

Audited to SOC 2 Type 2 and certified to ISO/IEC 27001, with the reports shared under NDA.

Frequently asked questions

Why are customer names not shown?

We do not publish customer names or logos. We describe each customer by sector, and we share references under NDA.

Can we speak to a customer in our sector?

Ask when you request a demo. We will try to introduce you to a customer in the same or a similar sector, under NDA.

Is xmodo itself audited?

Yes. xmodo is audited to SOC 2 Type 2 and certified to ISO/IEC 27001. We share the reports under NDA.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo