ISO/IEC 27001:2022 certificate
Full-scope ISMS certificate issued by TÜV Rheinland. Verify directly with the certification body — no hosted copy.
The enterprise security and compliance standards your product requires — certified, contracted, and documented.
Axon Active delivers regulated software under enterprise security and compliance controls — ISO/IEC 27001 certified since 2018, current to the 2022 standard, certified by TÜV Rheinland since 2021. We contract as your processor or sub-processor, depending on your role: DPA and EU SCCs in place before you sign, with the FDPIC-recognized Swiss adaptations for FADP transfers and the ICO’s UK International Data Transfer Addendum for UK GDPR. Our engineering teams are in Vietnam, where we operate under the Vietnamese PDPL, with transfer impact assessments and supplementary measures documented and available for review.
Data-protection and AI regulations differ by market. Pick a jurisdiction to see which rules apply, how our controls cover them, and the concrete proof or mechanism behind each claim.
Privacy and security controls are built into our ISMS and our ISO 27701-based privacy controls for GDPR and FADP. For AI engagements we allocate EU AI Act roles and obligations per engagement. As our home market, EU and Swiss requirements are the default configuration of every engagement — not an add-on.
Proof / mechanismUK GDPR is built on the same framework as EU GDPR, so our control set carries across; UK-specific transfer requirements are handled contractually per engagement.
Proof / mechanismAPAC has no single regional regulation; requirements are national. Our delivery sits within the region, and the same ISO/IEC 27001-certified ISMS and DPA framework apply throughout. Country-specific requirements are scoped with you at contracting — including Korea's consignment and overseas-transfer rules under PIPA, and Japan's supervision requirements for entrusted parties under the APPI. Where the ASEAN Model Contractual Clauses are the preferred transfer instrument, we contract on that basis.
Proof / mechanismAs the delivery location, Axon Active itself is subject to Vietnamese data-protection law; compliance is maintained under the same ISMS that covers client engagements.
Proof / mechanismUS privacy law is state-by-state rather than federal. Service-provider obligations under CCPA/CPRA are addressed in the DPA, and equivalent terms are added where other state laws apply. Security controls follow our ISO/IEC 27001-certified ISMS, which applies identically across all engagements regardless of market. US buyers frequently ask for SOC 2 — we do not hold a SOC 2 report, but maintain a mapping of our ISO 27001 Annex A controls to the AICPA Trust Services Criteria so your security team can assess us against the framework they already use.
Proof / mechanismWhere an engagement falls outside the markets above, our ISO/IEC 27001-certified control set and DPA framework apply as the baseline. Jurisdiction-specific requirements are scoped with you and your counsel at contracting, and reflected in the DPA before work begins.
Proof / mechanismCertified, compliant, aligned and applied are not interchangeable terms — four different levels of proof.
An accredited third party audited us and issued a certificate.
We meet the standard but have not pursued the certificate.
We follow the standard while formalization is still underway.
The standard is guidance that cannot be certified by design.
Certified since 2018 (SGS 2018–2021, TÜV Rheinland since 2021), the international standard for information security, our software development, software testing, and ICT services are delivered under independently audited controls that protect the confidentiality, integrity, and availability of your data.
A privacy extension to ISO 27001. It governs how we handle personal data (PII) and backs our compliance with privacy laws such as the EU's GDPR and Switzerland's FADP.
How Axon Active aligns AI engagements with the EU Artificial Intelligence Act (Regulation 2024/1689) — role allocation, transparency, human oversight, and Article 4 AI literacy.
ISO 14001 is an internationally recognized standard for environmental management systems, helping organizations improve their environmental performance. It provides a framework for organizations to manage their environmental responsibilities efficiently and sustainably.
The international standard for occupational health and safety. We run our workplace health, safety and wellbeing practices aligned with ISO 45001, so the people who build here are protected and supported.
Audited by TÜV Rheinland, SGS, Swiss Post and ePost Service AG. All findings closed. A visual summary of the full audit history is available on request.
Available immediately — no form required. Maintained by the Axon Security & Compliance team.
Full-scope ISMS certificate issued by TÜV Rheinland. Verify directly with the certification body — no hosted copy.
How Axon Active processes personal data under EU GDPR and Swiss FADP — including data subjects' rights, our EEA representative under Art. 27 GDPR, and contact details for privacy requests.
Available upon request — reviewed by our Security & Compliance team. Click any document to submit a request; a team member will be in touch within a few business days.
Full ISO/IEC 27001:2022 Annex A control inventory — implementation status and justification for every control.
Standard DPA template for client engagements covering GDPR and FADP obligations. Sub-processor list provided as an annex. A compliance team member will guide you through the document.
EU Commission SCCs for cross-border transfers (EU/CH → VN), including the Swiss annex (FDPIC-recognized) and the UK Addendum. A compliance team member will guide you through correct completion of the annexes.
Visual overview of Axon Active's audit track record — 13 external audits since 2018, 100% pass rate, all findings closed. Certified by TÜV Rheinland, SGS, Swiss Post, and ePost Service AG.
Overview of Axon Active's audit track record — external certification audits since 2018, all findings closed. Certification audits by SGS (2018–2021) and TÜV Rheinland (since 2021), supplemented by client security audits.
High-level summary of Axon Active's security posture, certifications, operational controls, and data-handling principles — for initial vendor assessments.
How Axon Active aligns AI engagements with the EU Artificial Intelligence Act (Regulation 2024/1689) — role allocation, transparency, human oversight, and Article 4 AI literacy.
Business continuity and disaster recovery procedures are documented and regularly tested within our ISO/IEC 27001:2022 certified ISMS. Available for discussion during contract negotiation or annual vendor review.
For specific questions, custom assessments, or to schedule a security review call — no form, just an email.
DPA, SCCs, GDPR and FADP questions, data subject requests.
Email: privacy@axonactive.com
Audit reports, Statement of Applicability, security questionnaires, business continuity.
Email: security@axonactive.com
No — and strictly speaking, no company is. SOC 2 is not a certification. It is an attestation report issued by a US-licensed CPA firm about a defined service organization, shared under NDA rather than published.
What Axon Active holds is ISO/IEC 27001:2022, the international standard for information security management, certified by an accredited certification body and publicly verifiable. We have been continuously certified since 2018 and hold a current certificate from TÜV Rheinland covering software development, software testing and ICT services.
Both assess an operating control environment rather than a product, and both are evaluated by an independent third party. The differences are in form, assessor and market.
The control overlap is substantial. ISO 27001 Annex A and the SOC 2 Common Criteria address the same underlying areas: access control, change management, incident response, supplier security, logging and monitoring, and business continuity. The difference is largely how the evidence is packaged for the reader.
We maintain a mapping of our ISO/IEC 27001 Annex A controls to the AICPA Trust Services Criteria (Security). It is available to clients and prospects on request under NDA, and lets your security team assess our control environment against the framework they already work with.
We have not undergone a SOC 2 examination and cannot provide a SOC 2 report. Where a client engagement genuinely requires one, we are open to discussing a scoped examination as part of that engagement.
Directly with the certification body, not with us. Our certificate is listed in TÜV Rheinland’s public Certipedia register, which shows the current certificate holder, standard, scope and validity in real time.
We deliberately do not host a PDF copy. A live entry in the certifier’s own register is stronger evidence than a file on our website.
13 external onsite audits since 2018, with a 100% pass rate and all findings closed. Certification audits were carried out by SGS from 2018 to 2021 and by TÜV Rheinland since 2021, supplemented by client security audits and audits by Swiss Post and ePost Service AG.
An audit report summary is available on request.
Yes, with the right instruments in place. Vietnam is not covered by an EU adequacy decision, so transfers rely on Article 46 safeguards: the EU Standard Contractual Clauses, attached to the DPA, together with a documented transfer impact assessment and the supplementary technical and organizational measures that follow from it.
Both the SCCs and the TIA are in place before you sign, not negotiated afterwards. The TIA assesses the legal environment at our Vietnam delivery locations and is reviewed annually.
We sign a DPA on every engagement involving personal data. Whether we act as your processor or as your sub-processor depends on your own role — if you are a processor for your customers, we sit beneath you in that chain, and the DPA is structured accordingly.
Our standard DPA template, with the sub-processor list as an annex, is available on request. A member of our compliance team will walk your legal counsel through it.
Yes — VGS Datenschutzpartner GmbH in Hamburg. Contact details are published in our Data Privacy Notice.
Both as standard, not as add-ons.
For UK GDPR, the ICO’s International Data Transfer Addendum is attached to the DPA. For Swiss FADP, we use the FDPIC-recognized Swiss adaptations to the EU SCCs. Switzerland is a home market for us, so Swiss requirements are the default configuration of an engagement rather than something scoped in later.
By default, no. Client data stays in client systems, and our engineers access those systems using credentials your side manages. Where an engagement requires data on Axon Active infrastructure, that is agreed in writing in advance and covered by the DPA.
We use AI-assisted development under our AI Usage Guidelines, on approved tooling only. In client engagements this typically means your tooling, in your environment, under your controls. Where an engagement calls for it, we can run inference on our own infrastructure instead.
Client data is never used to train or improve external models. If your organization restricts AI tooling entirely, we scope that at contracting.
We allocate AI Act roles and obligations per engagement, since the same delivery team can sit in a different position depending on what is being built and who places it on the market. Transparency, human oversight and data quality requirements are built into how we work, and under Article 4 we run AI-literacy training and internal AI Dojos so teams work with AI competently rather than casually.
An EU AI Act alignment statement is available on request.
Yes. Send it to security@axonactive.com — no form, no portal registration. Our Security & Compliance team handles questionnaires directly and typically responds within a few business days.
If it helps to talk first, we will schedule a security review call with the people who actually operate the controls.
Yes. Client security audits are part of our normal audit track record, and audit rights are set out in the DPA. In practice, many clients find that the certification audit reports, the Statement of Applicability and a review call answer their questions without a separate on-site audit — but the option is there.
As your processor, we notify you without undue delay, so that you can meet your own reporting obligations — the 72-hour controller deadline under GDPR, and the equivalent requirements under FADP, Vietnam’s PDPL and other applicable local regulations.
Our incident-response procedures are documented and tested regularly within our certified ISMS.