xmodoxmodo

Security

How we secure xmodo

xmodo runs its own security programme on the platform. Our controls are independently audited, customer accounts are separate, and every important action is recorded.

Security practices

Independently audited

Audited to SOC 2 Type 2 and certified to ISO/IEC 27001, with the reports shared under NDA.

Separate customer accounts

Each customer's programme runs in its own account. Demonstration accounts are separate from customer accounts.

Encryption

Data is encrypted in transit and at rest. We cover key management and data residency options on the scoping call.

Activity logs

xmodo records important actions with the person and the time. This includes every AI proposal and the decision made on it.

No training on your data

Your organisation's data is never used to train models. We state this here and in our agreement with you.

Penetration testing

An independent firm tests the platform every year. The summary is available in the trust centre under NDA.

Reporting a vulnerability

If you think you have found a vulnerability in xmodo, tell us through the contact form. Use the subject "security" and give enough detail for us to reproduce it. We acknowledge reports within two working days and keep you informed while we fix the issue. We do not take action against researchers who act in good faith and give us reasonable time to fix it.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo