Get in touch
Axon Active - enterprise security and compliance
COMPLIANCE

Built for enterprise security standards — not bolted on

Axon Active provides enterprise security and compliance for regulated software delivery — ISO/IEC 27001:2022 certified by TÜV Rheinland since 2018. Jurisdiction coverage across EU, UK, APAC, and Vietnam. DPA + SCC ready before you sign, for procurement, audit, and engineering leaders evaluating Axon Active.

17+Years in business
100%Swiss owned
40+Long-term clients
650+Employees
80+Dedicated teams
By jurisdiction

Which standards apply where and how we meet them

Data-protection and AI rules differ by market. Pick a jurisdiction to see which regulations apply, how our controls cover them, and the concrete proof or mechanism behind each claim.

EU / Switzerland

Key regulations
GDPR (EU) FADP (Switzerland) EU AI Act (Regulation 2024/1689)
How it's covered

Privacy and security controls are built into our ISMS/PIMS for GDPR and FADP; AI engagements are aligned with the EU AI Act. As our home market, EU and Swiss requirements are the default configuration of every engagement — not an add-on.

Proof / mechanism
  1. 01ISO 27001 certificate — verifiable on Certipedia
  2. 02ISO 27701 privacy controls (PIMS)
  3. 03DPA + EU SCC (2021/914, module 2) for VN → EU/CH transfers
Certifications

Security; privacy certifications and what each label means

Certified, compliant, aligned and applied are not interchangeable terms — four different levels of proof.

01Certified

An accredited third party audited us and issued a certificate.

Strongest proof · e.g. ISO/IEC 27001
02Compliant

We meet the standard but have not pursued the certificate.

Met in full · e.g. ISO/IEC 27701
03Aligned

We follow the standard while formalisation is still underway.

In practice today · e.g. EU AI Act
04Applied

The standard is guidance that cannot be certified by design.

Guidance only · e.g. ISO 26000
ISO/IEC 27001:2022

ISO/IEC 27001:2022 Certified

Certified by TÜV Rheinland to ISO/IEC 27001:2022, the international standard for information security, our software development, software testing, and ICT services are delivered under independently audited controls that protect the confidentiality, integrity, and availability of your data.

Cert #01 153 2035611 · since 2018

ISO/IEC 27701:2025

ISO/IEC 27701:2025 ISO/IEC 27701:2025

a privacy extension to ISO 27001. It governs how we handle personal data (PII) and backs our compliance with privacy laws such as the EU's GDPR and Switzerland's FADP.

Backbone of GDPR & FADP compliance

EU AI Act 2024/1689

EU AI Act 2024/1689 Aligned

We build AI in line with the EU AI Act (Regulation 2024/1689): transparency, human oversight and data quality on every engagement. Under Article 4, we run AI-literacy training and internal AI Dojos so every team works with AI responsibly.

Article 4 AI-literacy programme, all teams

ISO 45001:2018

ISO 45001:2018 In progress

The international standard for occupational health and safety. We run our workplace health, safety and wellbeing practices aligned with ISO 45001, so the people who build here are protected and supported.

Certification target: 2027

Data Handling

Client data, in plain terms

Photo — secure delivery team at work (ODC floor, badge access) browse files
Access
Engineers access client systems via client-managed credentials and secure connections.
Storage
No client data is stored or processed on Axon Active infrastructure unless explicitly agreed in writing.
Incidents
Documented, regularly tested incident-response procedures aligned with breach-notification requirements under GDPR (72 hours), FADP, Vietnam PDPL and applicable local regulations.
Continuity
Business continuity and disaster recovery are documented and tested as part of our full-scope ISO/IEC 27001:2022 certified ISMS.
Audit track record

13 external audits since 2018 100% pass rate

Audited by TÜV Rheinland, SGS, Swiss Post and ePost Service AG. All findings closed. A visual summary of the full audit history is available on request.

13external audits
100%pass rate
4independent audit bodies
2018continuously certified since
Public · no form

Public documentation — open access

Available immediately — no form required. Maintained by the Axon Security & Compliance team.

privacy@axonactive.com · updated quarterly

Public

ISO/IEC 27001:2022 certificate

Full-scope ISMS certificate issued by TÜV Rheinland. Verify directly on Certipedia — more trustworthy than a hosted PDF.

Live verification · Cert #01 1532035611 · Continuously certified since 2018
Public

Data Privacy Notice

How Axon Active processes personal data under EU GDPR and Swiss FADP — including data subjects' rights and contact details for privacy requests.

Web page · axonactive.com/data-privacy-notice
Public

Security overview (one-pager)

High-level summary of Axon Active's security posture, certifications, operational controls, and data-handling principles — for initial vendor assessments.

PDF · 1 page
Coming soon
Public

EU AI Act alignment statement

How Axon Active aligns AI engagements with the EU Artificial Intelligence Act (Regulation 2024/1689) — risk tiering, transparency, human oversight, and Article 4 AI literacy.

PDF · v1.0 · 2026
Coming soon
Gated · on request

Detailed reports & agreements

Available upon request — reviewed by our Security & Compliance team. Click any document to submit a request; a team member will be in touch within a few business days.

Gated

Statement of Applicability (SoA)

Full ISO/IEC 27001:2022 Annex A control inventory — implementation status and justification for every control.

PDF · SoA V1.9 · 2025-12-31
Gated

Data Processing Agreement (DPA)

Standard DPA template for client engagements covering GDPR and FADP obligations. Sub-processor list provided as an annex. A compliance team member will guide you through the document.

PDF · shared with compliance guidance
Gated

Standard Contractual Clauses (SCC)

EU Commission SCC (2021/914, module 2) for cross-border transfers (VN → EU/CH). A compliance team member will guide you through correct completion of the annexes.

PDF · EU 2021/914 module 2
Gated

Audit report summary

Visual overview of Axon Active's audit track record — 13 external audits since 2018, 100% pass rate, all findings closed. Certified by TÜV Rheinland, SGS, Swiss Post, and ePost Service AG.

PDF · updated annually
Info

Business continuity & DR

Business continuity and disaster recovery procedures are documented and regularly tested as part of our full-scope ISO/IEC 27001:2022 certified ISMS. Available for discussion during contract negotiation or annual vendor review.

Covered under ISO/IEC 27001:2022 certification
In progress

ISO/IEC 42001 — AI Management System

Axon Active is actively assessing alignment with ISO/IEC 42001:2023, the world's first international standard for AI management systems. Based on existing AI governance frameworks, risk tiering, and competence programmes, we estimate 50–65% alignment today. Certification is under evaluation as a strategic milestone for 2027.

Formalisation underway · Certification target: 2027
Talk to us

Direct line to our Security & Compliance team

For specific questions, custom assessments, or to schedule a security review call — no form, just an email.

Data privacy

DPA, SCC, GDPR / FADP questions, data subject requests.

Email: privacy@axonactive.com

Owner: Security & Compliance team

Security & audit

Audit reports, Statement of Applicability, business continuity, incident reporting.

Breach / incident: security@axonactive.com

Response: typically within a few business days