Legal

Compliance as a roadmap, not a claim.

We build DataNXT with regulatory compliance and data protection at the core of the platform architecture. This page sets out which standards we are working towards and where we currently stand.

Last updated: July 2026

Targeted, not certified. The standards named on this page describe our target state. At this point there are no completed external certifications or audit reports. We label each item accordingly and update this page as assessments complete. Please do not use these statements as evidence of certification in procurement or tender processes.

Our commitment

Three principles that drive the architecture.

Privacy

Privacy by design

The platform is designed from the ground up around data protection principles – aligned with the GDPR and beyond.

Regulation

Regulatory readiness

We are developing the policies, procedures, and technical controls needed to meet financial services regulation and industry standards.

Operations

Continuous monitoring

Ongoing monitoring, regular assessments, and improvement processes maintain the standard rather than reaching it once.

Targeted standards

What we want to be measured against.

In preparation

GDPR – General Data Protection Regulation

Requirements for data protection, data subject rights, and cross-border data transfers.

  • Data subject rights implementation
  • Privacy-by-design architecture
  • Data protection impact assessments
  • Breach notification procedures

In preparation

SOC 2 Type II

Controls for security, availability, processing integrity, confidentiality, and privacy.

  • Security control implementation
  • Availability monitoring systems
  • Processing integrity controls
  • Confidentiality safeguards

In preparation

ISO 27001 – Information security

An information security management system (ISMS) following international best practice.

  • Risk management framework
  • Security policy development
  • Incident response procedures
  • Continuous improvement processes

In preparation

ISO 27017 – Cloud security

Cloud-specific security controls and guidance for providers and their customers.

  • Cloud security architecture
  • Data segregation controls
  • Virtual network security
  • Cloud service monitoring

In preparation

ISO 27018 – Privacy in the cloud

Protection of privacy in cloud computing environments and handling of personally identifiable information.

  • PII protection controls
  • Consent management systems
  • Data location transparency
  • PII return and erasure

In preparation

Financial services regulation

Readiness for financial services regulatory requirements and industry-specific obligations.

  • Data retention policies
  • Audit trail requirements
  • Risk management controls
  • Regulatory reporting capabilities
Approach

Six steps, in this order.

  1. Requirements analysis

    Analysis of applicable regulations and industry standards to define our compliance requirements.

  2. Architecture design

    Designing the platform architecture with built-in compliance controls, security measures, and privacy safeguards.

  3. Policy development

    Creating the policies, procedures, and documentation that support the compliance framework.

  4. Implementation and testing

    Implementing the controls and testing them thoroughly to demonstrate effectiveness and reliability.

  5. Certification and audit

    Engaging external auditors and certification bodies to validate the implementation.

  6. Continuous monitoring

    Ongoing monitoring, assessment, and improvement of our compliance posture.

Questions about our compliance?

We answer questions about regulatory readiness and data protection practice – and say plainly what is not finished yet.