Security & Compliance · ISO/IEC 27001

In preparation, and honest about it.

We are working toward ISO/IEC 27001 certification. It is not yet held, and nothing on this page claims it. What you can do today: assess the shipped controls yourself, and file a standing request so the certificate reaches you the day it exists.

The certification track, station by station.

  1. 01 · Done Scoping & gap analysis

    The ISMS scope is drawn around how the product is built, released and operated; the gap list is the work plan.

  2. 02 · Done Controls & evidence

    Annex A controls implemented and generating evidence, most live in the product and pipeline, documented below.

  3. 03 · In progress Internal audit

    The ISMS is being audited against its own scope before anyone external looks; findings feed back into the controls.

  4. 04 · Then Certification audit

    An accredited body examines the ISMS; the certificate lands on this page, and with everyone whose request is standing.

No promised dates, a date named before the internal audit closes would be theatre. The state of the work is shareable at any time from your account.

The control themes, as shipped mechanisms.

Access control

Group permissions enforced inside every query; invitation-only accounts; write-only credentials; per-IP backoff and lockout on every sign-in surface

Cryptography

TLS in transit; secrets sealed server-side; releases, heartbeats and leases signed (Ed25519); webhook signatures verified per platform

Operations security

Single-tenant deployments, one database per client; hash-chained tamper-evident audit log; safety backup before every update, automatic rollback on failed health checks

Development security

Release gate on every build, static checks, the full test suite, signed artifacts; one failed gate blocks the release for the whole fleet

Supplier relationships

At most two sub-processor categories, none at all when self-hosting with self-hosted AI; the Naxis AI service runs under DPA with zero-retention terms

Incident readiness

Signed heartbeats with disturbance events; short-lived leases let a compromised instance be stopped remotely; support access to client instances is consent-gated per ticket

Each theme is documented in the trust library, readable now, no certificate required to verify a mechanism exists.

What to request, today and the day it lands.

Certificate Not yet held
ISO/IEC 27001 certificate

The certificate is not yet held and is not claimed anywhere on this site; the ISO 27001 page shows exactly where the track stands. A standing request is fulfilled the day the certificate exists, and the current state is shareable on your thread meanwhile.

Request it when ready

An account action, the request files under your Naxis account, and the answer arrives on its thread.

Overview Sent on request
Security & architecture overview

How a deployment is built: the single-tenant boundary, the permission model, the audit chain and the AI data flow: the document a security review starts with.

Request to see

An account action, the request files under your Naxis account, and the answer arrives on its thread.

Service Sent on request
Your security questionnaire, answered

Send your own questionnaire: CAIQ, SIG, or your in-house sheet, in the request note. Answers come from the architecture, not a boilerplate script.

Request to see

An account action, the request files under your Naxis account, and the answer arrives on its thread.

ISO 27001 status, answered

Is Naxis ISO 27001 certified?

Not yet. We are working toward ISO/IEC 27001 certification and say so plainly, no certificate is claimed anywhere on this site until one is held. The control themes the standard expects are shipped, assessable mechanisms today.

Can we deploy before you are certified?

Many organisations do exactly that: assess the controls directly, the architecture overview, the trust library, your own questionnaire answered from the architecture, sign the DPA, and file a standing request so the certificate reaches you the day it exists.

Can we see where the preparation actually stands?

Yes. Request it from your account and you get the current preparation state on your own thread, which track stage is in progress, what evidence exists, what remains. No glossy roadmap, the real state.

Who will the certification body be?

An accredited certification body, named on this page when the audit is engaged. We do not pre-announce a name we have not contracted.

Does self-hosting change the certification scope?

The ISMS covers how we build, release and operate the product and the managed fleet. A self-hosted deployment runs the same signed artifact on your infrastructure, your own physical and network controls apply there, and the product controls travel with it.

Assess the controls yourself.

The mechanisms are shipped and documented, a certificate will confirm them, not create them.