Compliance
Our control framework is designed against ISO 27001:2022 and the SOC 2 trust services criteria. Third-party certification reports will be published in this Trust Center as soon as they are available.
Controls View More ›
Product Security | (7 Controls)
- Secure Software Development Lifecycle established
- Penetration Testing conducted
- Change Management procedures enforced
- Vulnerability scanning procedures established
Access Management | (9 Controls)
- Role Based Access Control (RBAC) established
- Multi Factor Authentication implemented
- User Access Reviews conducted
- Password policy enforced
Security and Continuity Procedures | (7 Controls)
- Business Continuity and Disaster Recovery plans established
- Continuity and Disaster Recovery plans tested
- Incident Response plan tested
- Data backups and restoration procedures tested
Data Security | (4 Controls)
- Encryption at rest implemented
- Encryption in transit implemented
- Encryption key management process established
- Network and firewall access restricted
How we earn trust
We govern AI the way we ask you to
Argorix runs its own AI systems under the same discovery, guardrails, and red-team validation we provide to customers.
Evidence over claims
Security posture should be demonstrable. Everything Argorix enforces produces traceable evidence you can inspect.
You stay in control
Deployment model, data residency, and access policy are your decisions — Argorix adapts to your environment.
Controls
Product Security | (7 Controls)
Secure Software Development Lifecycle established
Security is embedded across the full development lifecycle - from design and code review to deployment and maintenance - so vulnerabilities are prevented rather than patched late.
Penetration Testing conducted
Third-party penetration tests simulate real attacks against our systems. Findings are triaged and remediation of critical issues is tracked to closure; a summary report is available under NDA.
Change Management procedures enforced
All software and infrastructure changes are reviewed, approved, and traceable before reaching production, linking each change to its request and review trail.
Vulnerability scanning procedures established
Application and host scans run against known CVEs on a recurring schedule. Critical and high findings are tracked until remediated under our vulnerability management process.
Secure product architecture defined
The production architecture and its components are documented and reviewed so that security boundaries, data flows, and trust zones are explicit.
Production environment segregation enforced
Production is segregated from development and staging environments, reducing the risk of unauthorized access or unintended changes to live systems.
Intrusion Detection systems utilized
Network and host activity is continuously monitored for anomalous behavior, enabling early detection and rapid response to potential intrusions.
Access Management | (9 Controls)
Role Based Access Control (RBAC) established
Access is granted strictly by role through a central identity provider, and the role matrix is reviewed regularly to preserve least privilege.
Multi Factor Authentication implemented
MFA is required for privileged accounts and any access to sensitive systems, adding a second layer beyond credentials.
User Access Reviews conducted
Scheduled reviews validate that access to production systems, databases, and applications matches current job responsibilities; each review is documented and signed off.
Password policy enforced
A password policy defines required strength and rotation across systems, and compliance is monitored.
Restricted production access maintained
Only authorized users with a documented business need can reach the production environment.
Privilege access restricted
Privileged access to critical systems is limited to authorized personnel with a justified need, keeping sensitive operations tightly controlled.
Access control policies and procedures defined
Formal policy covers how access is provisioned, modified, and revoked, and how often reviews take place.
Production database access restricted
Production databases are reachable only by authorized personnel, and production data is not used in development or testing unless strictly necessary.
Access request and approval process defined
Access is provisioned only after a documented request tied to role and function is approved by a manager.
Security and Continuity Procedures | (7 Controls)
Business Continuity and Disaster Recovery plans established
Formal BC/DR plans define how services and infrastructure are restored after a disruption, including communication paths when key personnel are unavailable.
Continuity and Disaster Recovery plans tested
BC/DR plans are exercised periodically, including backup integrity checks and restoration drills.
Incident Response plan tested
The incident response plan is exercised at least annually; results feed updates that strengthen detection, escalation, and handling.
Data backups and restoration procedures tested
Production data is backed up regularly and stored separately from production; restorations are tested to confirm integrity and recoverability.
Production multi-availability zones utilized
Production workloads run across multiple availability zones for redundancy and high availability.
Production monitoring implemented
Performance, availability, and security signals are monitored continuously so issues are detected early and handled promptly.
Audit logging established
Key events - logons, deletions, errors, and changes to software or configuration - are logged across application and infrastructure layers and monitored.
Data Security | (4 Controls)
Encryption at rest implemented
Stored data is protected with industry-accepted encryption standards such as AES-256.
Encryption in transit implemented
Data in transit is protected with TLS 1.2 or newer; deprecated protocols are disabled.
Encryption key management process established
Encryption keys are handled under a defined process that restricts access to authorized users with a valid business need.
Network and firewall access restricted
Firewalls limit unnecessary ports, protocols, and services, and rules are periodically reviewed and approved.
Organization Security | (10 Controls)
Risk Assessment and treatment established
A company-wide risk assessment runs at least annually with periodic follow-ups, evaluating threats, likelihood, and impact to define treatment and tolerance.
Vendor Risk Management established
New vendors are assessed before engagement and re-assessed periodically to catch emerging risks.
Asset Management maintained
Physical and virtual assets are inventoried with ownership, classification, and location, ensuring accountability for sensitive systems.
Security Awareness Training implemented
Employees complete security awareness training on hire and annually thereafter.
Secure Development LifeCycle (SDLC) Training implemented
Engineers receive recurring secure-development training aligned with the SDLC methodology and secure development policy.
Defined roles and responsibilities established
Security, availability, and confidentiality responsibilities are formally assigned through job descriptions and policy.
Service Level Agreement established
Service commitments and availability targets are defined contractually, with advance notice for planned maintenance.
Candidates screening checks
New hires and internal transfers are screened for qualifications and role suitability.
Confidentiality agreement acknowledged by employees
Every employee signs a confidentiality agreement during onboarding, covering company and customer information.
Coordinated responsible disclosure program
We welcome coordinated vulnerability reports at security@argorix.com and respond promptly to validated findings.
Endpoint Security | (4 Controls)
Endpoint Detection and Response established
EDR continuously monitors endpoints to detect and respond to threats.
Disk encryption enforced
Organizational devices enforce full-disk encryption (AES-256), including media that stores personal data.
Threat and Malware protection enforced
Endpoints run real-time detection, prevention, and removal of malicious software.
Endpoint Management policies established
Managed devices must meet baseline policy: strong passwords, anti-malware, and disk encryption.
AI Governance | (5 Controls)
Adversarial AI red-team validation of our own systems
Argorix runs the same adversarial red-team validation on its own AI systems that it provides to customers.
Runtime guardrails enforced on our own AI
Our internal AI runtime operates under the same guardrails and policy enforcement we ship in the platform.
AI system inventory maintained
We apply our own discovery to keep a live inventory of the models and agents we operate.
Data minimization with redaction at the source
We collect only what is needed to govern AI risk, and sensitive content is redacted at the source wherever detection allows.
On-premise deployment option
When residency or policy requires it, customers can deploy on-premise so AI telemetry never leaves their environment.
Need the full control matrix mapped to ISO 27001 / SOC 2 criteria? Request access to our security documentation.
Subprocessors
Argorix uses a deliberately small set of third-party providers. For on-premise deployments, customer AI telemetry stays entirely inside the customer environment and is not shared with any subprocessor.
| Subprocessor | Purpose | Location |
|---|---|---|
| V2Nets | Web hosting infrastructure for argorix.com public sites and this Trust Center | Chile |
| Google LLC | Web font delivery (Google Fonts) on public websites | United States |
Last reviewed: August 1, 2026. We review this list on changes to our infrastructure and notify customers of material subprocessor changes as part of our agreements.