Trust Centre
Compliance & Certifications
Last updated August 2026 · v1.4 · Changelog
ISO/IEC 27001:2022
Certified
UK GDPR / Data Protection Act 2018
Compliant
SOC 2 Type II
Planned for Q1 2027
Cyber Essentials
Planned for Q4 2026
Certification status
| Framework | Status | Detail |
|---|---|---|
| ISO/IEC 27001:2022 | Certified | Certificate 267181, valid to 05 October 2028 (annual surveillance assessments) |
| UK GDPR / Data Protection Act 2018 | Compliant | Privacy Policy v2.0 and DPA in place, published at trust.vixio.com |
| SOC 2 Type II | Planned for Q1 2027 | On roadmap, target certification Q1 2027 |
| Cyber Essentials | Planned for Q4 2026 | UK Government scheme, certification planned for Q4 2026 |
ISO 27001:2022 detail
Certified, active
| Certificate number | 267181 |
|---|---|
| Issued by | British Assessment Bureau (Amtivo Group), UKAS accreditation 8289 |
| Valid from | 06 October 2025 |
| Expiry | 05 October 2028 (annual surveillance) |
| Scope | Development, delivery, and ongoing operation of Vixio's cloud-based platforms and associated services, including the processing of customer, employee, and supplier information across infrastructure, endpoints, and SaaS systems. |
UK GDPR / Data Protection Act 2018
Compliance Online Limited is the data controller of personal data collected from users in connection with the Services. Vixio maintains a Privacy Policy (v2.0, May 2026) and a Data Processing Agreement governing personal data processing on behalf of customer organisations. International transfers are made under EU SCCs with UK Addendum or UK IDTAs as applicable. See the Data Privacy page for the summary, or the full Privacy Policy for complete detail.
SOC 2 Type II roadmap
SOC 2 Type II is on the Vixio compliance roadmap with a target certification date of Q1 2027. Vixio will publish observation period and auditor information when the programme commences.
Cyber Essentials detail
| Scheme | UK Government Cyber Essentials |
|---|---|
| Certificate number | Not yet issued |
