Skip to content

Trust Centre

Compliance & Certifications

Last updated August 2026 · v1.4 · Changelog

ISO/IEC 27001:2022

Certified

UK GDPR / Data Protection Act 2018

Compliant

SOC 2 Type II

Planned for Q1 2027

Cyber Essentials

Planned for Q4 2026

Certification status

FrameworkStatusDetail
ISO/IEC 27001:2022CertifiedCertificate 267181, valid to 05 October 2028 (annual surveillance assessments)
UK GDPR / Data Protection Act 2018CompliantPrivacy Policy v2.0 and DPA in place, published at trust.vixio.com
SOC 2 Type IIPlanned for Q1 2027On roadmap, target certification Q1 2027
Cyber EssentialsPlanned for Q4 2026UK Government scheme, certification planned for Q4 2026

ISO 27001:2022 detail

Certified, active

Certificate number267181
Issued byBritish Assessment Bureau (Amtivo Group), UKAS accreditation 8289
Valid from06 October 2025
Expiry05 October 2028 (annual surveillance)
ScopeDevelopment, delivery, and ongoing operation of Vixio's cloud-based platforms and associated services, including the processing of customer, employee, and supplier information across infrastructure, endpoints, and SaaS systems.

UK GDPR / Data Protection Act 2018

Compliance Online Limited is the data controller of personal data collected from users in connection with the Services. Vixio maintains a Privacy Policy (v2.0, May 2026) and a Data Processing Agreement governing personal data processing on behalf of customer organisations. International transfers are made under EU SCCs with UK Addendum or UK IDTAs as applicable. See the Data Privacy page for the summary, or the full Privacy Policy for complete detail.

SOC 2 Type II roadmap

Planned for Q1 2027

SOC 2 Type II is on the Vixio compliance roadmap with a target certification date of Q1 2027. Vixio will publish observation period and auditor information when the programme commences.

Cyber Essentials detail

Planned for Q4 2026
SchemeUK Government Cyber Essentials
Certificate numberNot yet issued