ISO/IEC 27001:2022 certificate
Full-scope ISMS certificate issued by TÜV Rheinland. Verify directly on Certipedia — more trustworthy than a hosted PDF.
Axon Active provides enterprise security and compliance for regulated software delivery — ISO/IEC 27001:2022 certified by TÜV Rheinland since 2018. Jurisdiction coverage across EU, UK, APAC, and Vietnam. DPA + SCC ready before you sign, for procurement, audit, and engineering leaders evaluating Axon Active.
Data-protection and AI rules differ by market. Pick a jurisdiction to see which regulations apply, how our controls cover them, and the concrete proof or mechanism behind each claim.
Privacy and security controls are built into our ISMS/PIMS for GDPR and FADP; AI engagements are aligned with the EU AI Act. As our home market, EU and Swiss requirements are the default configuration of every engagement — not an add-on.
Proof / mechanismUK GDPR retains the EU GDPR framework, so the same control set applies without modification; transfer requirements are handled contractually per engagement.
Proof / mechanismService-provider obligations under CCPA/CPRA are addressed in the DPA; security controls follow ISO/IEC 27001, our audited framework for information security.
Proof / mechanismAs the delivery location, Axon Active itself is subject to Vietnamese data-protection law; compliance is maintained under the same ISMS that covers client engagements.
Proof / mechanismCertified, compliant, aligned and applied are not interchangeable terms — four different levels of proof.
An accredited third party audited us and issued a certificate.
We meet the standard but have not pursued the certificate.
We follow the standard while formalisation is still underway.
The standard is guidance that cannot be certified by design.
Certified by TÜV Rheinland to ISO/IEC 27001:2022, the international standard for information security, our software development, software testing, and ICT services are delivered under independently audited controls that protect the confidentiality, integrity, and availability of your data.
a privacy extension to ISO 27001. It governs how we handle personal data (PII) and backs our compliance with privacy laws such as the EU's GDPR and Switzerland's FADP.
We build AI in line with the EU AI Act (Regulation 2024/1689): transparency, human oversight and data quality on every engagement. Under Article 4, we run AI-literacy training and internal AI Dojos so every team works with AI responsibly.
The international standard for occupational health and safety. We run our workplace health, safety and wellbeing practices aligned with ISO 45001, so the people who build here are protected and supported.
Audited by TÜV Rheinland, SGS, Swiss Post and ePost Service AG. All findings closed. A visual summary of the full audit history is available on request.
Available immediately — no form required. Maintained by the Axon Security & Compliance team.
Full-scope ISMS certificate issued by TÜV Rheinland. Verify directly on Certipedia — more trustworthy than a hosted PDF.
How Axon Active processes personal data under EU GDPR and Swiss FADP — including data subjects' rights and contact details for privacy requests.
High-level summary of Axon Active's security posture, certifications, operational controls, and data-handling principles — for initial vendor assessments.
How Axon Active aligns AI engagements with the EU Artificial Intelligence Act (Regulation 2024/1689) — risk tiering, transparency, human oversight, and Article 4 AI literacy.
Available upon request — reviewed by our Security & Compliance team. Click any document to submit a request; a team member will be in touch within a few business days.
Full ISO/IEC 27001:2022 Annex A control inventory — implementation status and justification for every control.
Standard DPA template for client engagements covering GDPR and FADP obligations. Sub-processor list provided as an annex. A compliance team member will guide you through the document.
EU Commission SCC (2021/914, module 2) for cross-border transfers (VN → EU/CH). A compliance team member will guide you through correct completion of the annexes.
Visual overview of Axon Active's audit track record — 13 external audits since 2018, 100% pass rate, all findings closed. Certified by TÜV Rheinland, SGS, Swiss Post, and ePost Service AG.
Business continuity and disaster recovery procedures are documented and regularly tested as part of our full-scope ISO/IEC 27001:2022 certified ISMS. Available for discussion during contract negotiation or annual vendor review.
Axon Active is actively assessing alignment with ISO/IEC 42001:2023, the world's first international standard for AI management systems. Based on existing AI governance frameworks, risk tiering, and competence programmes, we estimate 50–65% alignment today. Certification is under evaluation as a strategic milestone for 2027.
For specific questions, custom assessments, or to schedule a security review call — no form, just an email.
DPA, SCC, GDPR / FADP questions, data subject requests.
Email: privacy@axonactive.com
Owner: Security & Compliance team
Audit reports, Statement of Applicability, business continuity, incident reporting.
Breach / incident: security@axonactive.com
Response: typically within a few business days