Security
How we secure xmodo
xmodo runs its own security programme on the platform. Our controls are independently audited, customer accounts are separate, and every important action is recorded.
Security practices
Independently audited
Audited to SOC 2 Type 2 and certified to ISO/IEC 27001, with the reports shared under NDA.
Separate customer accounts
Each customer's programme runs in its own account. Demonstration accounts are separate from customer accounts.
Encryption
Data is encrypted in transit and at rest. We cover key management and data residency options on the scoping call.
Activity logs
xmodo records important actions with the person and the time. This includes every AI proposal and the decision made on it.
No training on your data
Your organisation's data is never used to train models. We state this here and in our agreement with you.
Penetration testing
An independent firm tests the platform every year. The summary is available in the trust centre under NDA.
Reporting a vulnerability
If you think you have found a vulnerability in xmodo, tell us through the contact form. Use the subject "security" and give enough detail for us to reproduce it. We acknowledge reports within two working days and keep you informed while we fix the issue. We do not take action against researchers who act in good faith and give us reasonable time to fix it.