Enterprise security and compliance
COMPLIANCE

Built for
enterprise standards

The enterprise security and compliance standards your product requires — certified, contracted, and documented.

17+Years in business
100%Swiss owned
40+Long-term clients
650+Employees
80+Dedicated teams

Axon Active delivers regulated software under enterprise security and compliance controls — ISO/IEC 27001 certified since 2018, current to the 2022 standard, certified by TÜV Rheinland since 2021. We contract as your processor or sub-processor, depending on your role: DPA and EU SCCs in place before you sign, with the FDPIC-recognized Swiss adaptations for FADP transfers and the ICO’s UK International Data Transfer Addendum for UK GDPR. Our engineering teams are in Vietnam, where we operate under the Vietnamese PDPL, with transfer impact assessments and supplementary measures documented and available for review.

By jurisdiction

Which regulations apply where and how we meet them

Data-protection and AI regulations differ by market. Pick a jurisdiction to see which rules apply, how our controls cover them, and the concrete proof or mechanism behind each claim.

EU / Switzerland

Key regulations
GDPR (EU) FADP (Switzerland) EU AI Act (Regulation 2024/1689)
How it's covered

Privacy and security controls are built into our ISMS and our ISO 27701-based privacy controls for GDPR and FADP. For AI engagements we allocate EU AI Act roles and obligations per engagement. As our home market, EU and Swiss requirements are the default configuration of every engagement — not an add-on.

Proof / mechanism
  1. 01DPA + EU Standard Contractual Clauses for EU/CH → Vietnam transfers
  2. 02Swiss annex to the EU SCCs (FDPIC-recognized) for FADP transfers
  3. 03Transfer impact assessment and supplementary measures — available for review
  4. 04EEA data protection representative under Art. 27 GDPR — VGS Datenschutzpartner GmbH, Hamburg
  5. 05AI Act role allocation and AI usage guidelines defined per engagement
  6. 06ISO/IEC 27001 certified (TÜV Rheinland) — verify on Certipedia
  7. 07Privacy controls compliant with ISO/IEC 27701 — the international privacy management standard applied within our certified ISMS
  8. 08ISO 27001 Statement of Applicability (SoA) — available on request
Certifications

Security; privacy certifications and what each label means

Certified, compliant, aligned and applied are not interchangeable terms — four different levels of proof.

01Certified

An accredited third party audited us and issued a certificate.

Strongest proof · e.g. ISO/IEC 27001
02Compliant

We meet the standard but have not pursued the certificate.

Met in full · e.g. ISO/IEC 27701
03Aligned

We follow the standard while formalization is still underway.

In practice today · e.g. EU AI Act
04Applied

The standard is guidance that cannot be certified by design.

Guidance only · e.g. ISO 26000

ISO/IEC 27001:2022 Certified

Certified since 2018 (SGS 2018–2021, TÜV Rheinland since 2021), the international standard for information security, our software development, software testing, and ICT services are delivered under independently audited controls that protect the confidentiality, integrity, and availability of your data.

Cert #01 153 2035611

ISO/IEC 27001:2022
Verify on Certipedia →

ISO/IEC 27701:2025 Compliant

A privacy extension to ISO 27001. It governs how we handle personal data (PII) and backs our compliance with privacy laws such as the EU's GDPR and Switzerland's FADP.

Backbone of GDPR & FADP compliance

ISO/IEC 27701:2025
About ISO 27701 →

EU AI Act 2024/1689 Aligned

How Axon Active aligns AI engagements with the EU Artificial Intelligence Act (Regulation 2024/1689) — role allocation, transparency, human oversight, and Article 4 AI literacy.

Article 4 AI-literacy program, all teams

EU AI Act 2024/1689
About the EU AI Act →

ISO 14001:2015 Compliant

ISO 14001 is an internationally recognized standard for environmental management systems, helping organizations improve their environmental performance. It provides a framework for organizations to manage their environmental responsibilities efficiently and sustainably.

Certification target: 2027

ISO 45001:2018
About ISO 14001:2015→

ISO 45001:2018 Compliant

The international standard for occupational health and safety. We run our workplace health, safety and wellbeing practices aligned with ISO 45001, so the people who build here are protected and supported.

Certification target: 2027

ISO 45001:2018
About ISO 45001 →
Data Handling

Client data, in plain terms

Photo — secure delivery team at work (ODC floor, badge access)
Access
Engineers access client systems via client-managed credentials and secure connections.
Storage
Client data stays in client systems. Where an engagement requires data on Axon Active infrastructure, it is agreed in writing and covered by the DPA.
AI tooling
AI-assisted development runs on approved tooling under our AI Usage Guidelines — in client engagements, typically your tooling in your environment. Where an engagement calls for it, we can run inference on our own infrastructure instead. Client data is never used to train or improve external models.
Incidents
Documented, regularly tested incident-response procedures. As processor we notify you without undue delay, so you can meet your own reporting obligations under GDPR (72 hours), FADP, Vietnam PDPL and applicable local regulations.
Continuity
Business continuity and disaster recovery are documented and tested within our ISO/IEC 27001:2022 certified ISMS.
Audit track record

13 external onsite audits since 2018 100% pass rate

Audited by TÜV Rheinland, SGS, Swiss Post and ePost Service AG. All findings closed. A visual summary of the full audit history is available on request.

13 external onsite audits
100%pass rate
4independent external audits
2018continuously certified since
Public · no form

Public documentation — open access

Available immediately — no form required. Maintained by the Axon Security & Compliance team.

Contact privacy@axonactive.com for data protection, security@axonactive.com for audit and security.

ISO/IEC 27001:2022 certificate

Full-scope ISMS certificate issued by TÜV Rheinland. Verify directly with the certification body — no hosted copy.

Live verification · Cert #01 1532035611 · Continuously certified since 2018

Data Privacy Notice

How Axon Active processes personal data under EU GDPR and Swiss FADP — including data subjects' rights, our EEA representative under Art. 27 GDPR, and contact details for privacy requests.

Web page · axonactive.com/data-privacy-notice
Gated · on request

Detailed reports & agreements

Available upon request — reviewed by our Security & Compliance team. Click any document to submit a request; a team member will be in touch within a few business days.

Statement of Applicability (SoA)

Full ISO/IEC 27001:2022 Annex A control inventory — implementation status and justification for every control.

PDF

Data Processing Agreement (DPA)

Standard DPA template for client engagements covering GDPR and FADP obligations. Sub-processor list provided as an annex. A compliance team member will guide you through the document.

PDF · shared with compliance guidance

Standard Contractual Clauses (SCC)

EU Commission SCCs for cross-border transfers (EU/CH → VN), including the Swiss annex (FDPIC-recognized) and the UK Addendum. A compliance team member will guide you through correct completion of the annexes.

PDF · EU 2021/914 module 2

Audit report summary

Visual overview of Axon Active's audit track record — 13 external audits since 2018, 100% pass rate, all findings closed. Certified by TÜV Rheinland, SGS, Swiss Post, and ePost Service AG.

PDF · updated annually

Transfer impact assessment (TIA)

Overview of Axon Active's audit track record — external certification audits since 2018, all findings closed. Certification audits by SGS (2018–2021) and TÜV Rheinland (since 2021), supplemented by client security audits.

Security overview (one-pager)

High-level summary of Axon Active's security posture, certifications, operational controls, and data-handling principles — for initial vendor assessments.

PDF

EU AI Act alignment statement

How Axon Active aligns AI engagements with the EU Artificial Intelligence Act (Regulation 2024/1689) — role allocation, transparency, human oversight, and Article 4 AI literacy.

PDF

Business continuity & DR

Business continuity and disaster recovery procedures are documented and regularly tested within our ISO/IEC 27001:2022 certified ISMS. Available for discussion during contract negotiation or annual vendor review.

Covered under ISO/IEC 27001:2022 certification
Talk to us

Direct line to our Security & Compliance team

For specific questions, custom assessments, or to schedule a security review call — no form, just an email.

Data privacy

DPA, SCCs, GDPR and FADP questions, data subject requests.

Email: privacy@axonactive.com

Security & audit

Audit reports, Statement of Applicability, security questionnaires, business continuity.

Email: security@axonactive.com

FAQs

Frequently asked questions

Is Axon Active SOC 2 certified?

No — and strictly speaking, no company is. SOC 2 is not a certification. It is an attestation report issued by a US-licensed CPA firm about a defined service organization, shared under NDA rather than published.

What Axon Active holds is ISO/IEC 27001:2022, the international standard for information security management, certified by an accredited certification body and publicly verifiable. We have been continuously certified since 2018 and hold a current certificate from TÜV Rheinland covering software development, software testing and ICT services.

What is the difference between ISO 27001 and SOC 2?

Both assess an operating control environment rather than a product, and both are evaluated by an independent third party. The differences are in form, assessor and market.

The control overlap is substantial. ISO 27001 Annex A and the SOC 2 Common Criteria address the same underlying areas: access control, change management, incident response, supplier security, logging and monitoring, and business continuity. The difference is largely how the evidence is packaged for the reader.

Our security review requires SOC 2. What can you provide?

We maintain a mapping of our ISO/IEC 27001 Annex A controls to the AICPA Trust Services Criteria (Security). It is available to clients and prospects on request under NDA, and lets your security team assess our control environment against the framework they already work with.

We have not undergone a SOC 2 examination and cannot provide a SOC 2 report. Where a client engagement genuinely requires one, we are open to discussing a scoped examination as part of that engagement.

How do we verify your ISO 27001 certificate?

Directly with the certification body, not with us. Our certificate is listed in TÜV Rheinland’s public Certipedia register, which shows the current certificate holder, standard, scope and validity in real time.

Verify on Certipedia →

We deliberately do not host a PDF copy. A live entry in the certifier’s own register is stronger evidence than a file on our website.

Is Axon Active certified to ISO/IEC 27701?

13 external onsite audits since 2018, with a 100% pass rate and all findings closed. Certification audits were carried out by SGS from 2018 to 2021 and by TÜV Rheinland since 2021, supplemented by client security audits and audits by Swiss Post and ePost Service AG.

An audit report summary is available on request.

Our data will be processed in Vietnam. Is that permitted under the GDPR?

Yes, with the right instruments in place. Vietnam is not covered by an EU adequacy decision, so transfers rely on Article 46 safeguards: the EU Standard Contractual Clauses, attached to the DPA, together with a documented transfer impact assessment and the supplementary technical and organizational measures that follow from it.

Both the SCCs and the TIA are in place before you sign, not negotiated afterwards. The TIA assesses the legal environment at our Vietnam delivery locations and is reviewed annually.

Do you sign a DPA, and are you a processor or a sub-processor?

We sign a DPA on every engagement involving personal data. Whether we act as your processor or as your sub-processor depends on your own role — if you are a processor for your customers, we sit beneath you in that chain, and the DPA is structured accordingly.

Our standard DPA template, with the sub-processor list as an annex, is available on request. A member of our compliance team will walk your legal counsel through it.

Do you have an EEA representative under Article 27 GDPR?

Yes — VGS Datenschutzpartner GmbH in Hamburg. Contact details are published in our Data Privacy Notice.

How are UK and Swiss transfers handled?

Both as standard, not as add-ons.

For UK GDPR, the ICO’s International Data Transfer Addendum is attached to the DPA. For Swiss FADP, we use the FDPIC-recognized Swiss adaptations to the EU SCCs. Switzerland is a home market for us, so Swiss requirements are the default configuration of an engagement rather than something scoped in later.

Does Axon Active store our data?

By default, no. Client data stays in client systems, and our engineers access those systems using credentials your side manages. Where an engagement requires data on Axon Active infrastructure, that is agreed in writing in advance and covered by the DPA.

Do you use AI tools, and is our code or data used to train models?

We use AI-assisted development under our AI Usage Guidelines, on approved tooling only. In client engagements this typically means your tooling, in your environment, under your controls. Where an engagement calls for it, we can run inference on our own infrastructure instead.

Client data is never used to train or improve external models. If your organization restricts AI tooling entirely, we scope that at contracting.

How do you handle the EU AI Act?

We allocate AI Act roles and obligations per engagement, since the same delivery team can sit in a different position depending on what is being built and who places it on the market. Transparency, human oversight and data quality requirements are built into how we work, and under Article 4 we run AI-literacy training and internal AI Dojos so teams work with AI competently rather than casually.

An EU AI Act alignment statement is available on request.

Will you complete our security questionnaire?

Yes. Send it to security@axonactive.com — no form, no portal registration. Our Security & Compliance team handles questionnaires directly and typically responds within a few business days.

If it helps to talk first, we will schedule a security review call with the people who actually operate the controls.

Can we audit Axon Active?

Yes. Client security audits are part of our normal audit track record, and audit rights are set out in the DPA. In practice, many clients find that the certification audit reports, the Statement of Applicability and a review call answer their questions without a separate on-site audit — but the option is there.

How quickly are we notified of a security incident?

As your processor, we notify you without undue delay, so that you can meet your own reporting obligations — the 72-hour controller deadline under GDPR, and the equivalent requirements under FADP, Vietnam’s PDPL and other applicable local regulations.

Our incident-response procedures are documented and tested regularly within our certified ISMS.