Customers
Organisations that run their compliance on xmodo
Organisations in banking, government, healthcare, information technology and e-commerce use xmodo to meet the regulations and standards that apply to them. We do not publish customer names.
Our customers
Sectors we serve
Our customers work in these sectors. Each answers to more than one regulator or standard.
Banking
Banks answer to their central bank, the card schemes and data protection authorities at the same time, and examiners expect evidence that controls worked throughout the period under review. xmodo holds each regulation's requirements, owners and evidence in one place. When an incident is classified, the regulator's reporting deadlines start on the incident record.
Government
Government entities follow national information assurance standards, and often the rules of an emirate or sector authority as well. Audits come from more than one direction. xmodo sets up each standard under its official title and edition, and links every audit finding to the corrective action that closes it.
Healthcare
Health regulators expect patient information to be protected across every hospital, clinic and system. xmodo runs the regulatory, privacy and security programme on one set of controls, so each control is implemented once and counts towards every standard that requires it.
Information technology
Technology companies that sell to large enterprises receive security questionnaires and audit requests from customers in many countries, alongside their own SOC 2 and ISO 27001 audits. xmodo keeps one set of evidence for their certifications and drafts answers to customer questionnaires from the same record.
E-commerce
Online retailers take card payments and hold personal data about large numbers of customers. They must meet PCI DSS and the data protection laws of each market they sell into. xmodo collects evidence from their cloud and payment systems through integrations, and raises a renewal task before any item expires.
In common
What xmodo changes for them
The sectors differ, but the work is the same: several frameworks, evidence that must stay current, and decisions that an examiner can review.
One set of controls
Each control is implemented once and counts towards every framework it satisfies. Adding a framework shows how much of it existing controls already cover.
Evidence that stays current
Evidence has an owner and an expiry date. A renewal task is raised before anything lapses, so auditors do not find out-of-date evidence first.
AI with recorded approval
The AI drafts mappings, policies and questionnaire answers. A named person approves each one, and the audit trail records the decision.
References
Speak to a customer
We arrange customer references under NDA. Ask for one when you get a demo, and we will try to introduce you to a customer in a sector close to yours.
Audited to SOC 2 Type 2 and certified to ISO/IEC 27001, with the reports shared under NDA.
Frequently asked questions
Why are customer names not shown?
We do not publish customer names or logos. We describe each customer by sector, and we share references under NDA.
Can we speak to a customer in our sector?
Ask when you request a demo. We will try to introduce you to a customer in the same or a similar sector, under NDA.
Is xmodo itself audited?
Yes. xmodo is audited to SOC 2 Type 2 and certified to ISO/IEC 27001. We share the reports under NDA.