Skip to content

Trust Centre

Security

Last updated August 2026 · v1.4 · Changelog

A2.1 Security Programme

Vixio maintains an Information Security Management System (ISMS) aligned to ISO/IEC 27001:2022, governed by a formal Information Security Policy reviewed annually. The ISMS covers all employees, contractors, suppliers, and stakeholders interacting with Vixio's information systems, data, or infrastructure, including personal devices under BYOD arrangements. Security responsibilities are designated within the technology team, with the CTO serving as ISMS Lead. Executive management provides leadership, budget, and oversight of ISMS objectives.

A2.2 ISO 27001 Certification

StandardISO/IEC 27001:2022
StatusCertified, active
Certificate number267181
Issued byBritish Assessment Bureau (Amtivo Group), UKAS accreditation 8289
Valid from06 October 2025
Expiry date05 October 2028 (subject to annual surveillance assessments)
ScopeDevelopment, delivery, and ongoing operation of Vixio's cloud-based platforms and associated services, including the processing of customer, employee, and supplier information across infrastructure, endpoints, and SaaS systems.
CertificateAvailable on request from tech@vixio.com

A2.3 Cyber Essentials

SchemeUK Government Cyber Essentials
StatusPlanned for Q4 2026
Certificate numberNot yet issued

A2.4 Infrastructure Security

  • Encryption in transit (TLS 1.2 or higher) and encryption at rest for all cloud-hosted personal data.
  • Network segmentation, firewall controls, and intrusion detection.
  • Centralised logging, monitoring, and automated alerting.
  • Regular vulnerability scanning and annual penetration testing by a qualified third-party provider.
  • Cloud infrastructure hosted on Amazon Web Services (AWS) with enterprise-grade security controls.

A2.5 Access Controls

  • Role-based access control (RBAC) across all environments.
  • Multi-factor authentication (MFA) enforced for all Vixio staff on production systems.
  • Privileged access management for infrastructure with quarterly access reviews.
  • Single sign-on (SSO) available for enterprise subscribers.
  • Principle of least privilege enforced.

Subscriber-side credential obligations, including the requirement that Users keep login details confidential and notify Vixio of suspected compromise, are set out in the Acceptable Use Policy.

A2.6 Vulnerability Disclosure

Report vulnerabilities to tech@vixio.com. Do not exploit, publicly disclose, or use the vulnerability against third-party systems. Provide sufficient information to reproduce the issue. For valid reports, Vixio will:

  • Acknowledge receipt within 3 business days.
  • Handle your report confidentially.
  • Not take legal action against good-faith disclosures.
  • Credit you on the disclosure unless you prefer otherwise.

A2.7 Incident Response

  • Documented incident response procedure maintained and tested.
  • Confirmed or suspected personal data breach notified to affected customers within 48 hours.
  • Written incident report available on request following a confirmed breach.
  • Ongoing remediation communications provided throughout the incident lifecycle.