Compliance
Our control framework is designed against ISO 27001:2022 and the SOC 2 trust services criteria. Third-party certification reports will be published in this Trust Center as soon as they are available.
Controls View More ›
Product Security | (6 Controls)
- Secure Software Development Lifecycle established
- Adversarial AI red-team validation of our own systems
- Change Management procedures enforced
- Vulnerability scanning procedures established
Access Management | (6 Controls)
- Role Based Access Control (RBAC) established
- Single Sign-On support with least-privilege defaults
- User access reviews conducted
- Reviewable audit log of access and decisions
Data Security | (6 Controls)
- Encryption at rest implemented
- Encryption in transit implemented
- Data minimization with redaction at the source
- Network and firewall access restricted
Security and Continuity | (6 Controls)
- Business Continuity and Disaster Recovery plans established
- Incident Response plan tested
- Data backups and restoration procedures tested
- Coordinated responsible disclosure program
How we earn trust
We govern AI the way we ask you to
Argorix runs its own AI systems under the same discovery, guardrails, and red-team validation we provide to customers.
Evidence over claims
Security posture should be demonstrable. Everything Argorix enforces produces traceable evidence you can inspect.
You stay in control
Deployment model, data residency, and access policy are your decisions — Argorix adapts to your environment.
Controls
Product Security | (6 Controls)
- Secure Software Development Lifecycle established
- Code review required before production changes
- Dependency and vulnerability scanning established
- Change Management procedures enforced
- Adversarial AI red-team validation of our own systems
- Guardrails enforced on our own AI runtime
Access Management | (6 Controls)
- Role Based Access Control (RBAC) established
- Single Sign-On support for enterprise deployments
- Least-privilege defaults on every role
- User access reviews conducted
- Strong password policy enforced
- Reviewable audit log of access and decisions
Data Security | (6 Controls)
- Encryption at rest implemented
- Encryption in transit implemented (TLS)
- Data minimization — we collect only what governs AI risk
- Sensitive content redacted at the source where detection allows
- On-premise deployment option — telemetry never leaves your environment
- Network and firewall access restricted
Security and Continuity | (6 Controls)
- Business Continuity and Disaster Recovery plans established
- Continuity and Disaster Recovery plans tested
- Incident Response plan tested
- Data backups and restoration procedures tested
- Monitoring and alerting on platform health
- Coordinated responsible disclosure program
Need the full control matrix mapped to ISO 27001 / SOC 2 criteria? Request access to our security documentation.
Subprocessors
Argorix uses a deliberately small set of third-party providers. For on-premise deployments, customer AI telemetry stays entirely inside the customer environment and is not shared with any subprocessor.
| Subprocessor | Purpose | Location |
|---|---|---|
| V2Nets | Web hosting infrastructure for argorix.com public sites and this Trust Center | Chile |
| Google LLC | Web font delivery (Google Fonts) on public websites | United States |
Last reviewed: August 1, 2026. We review this list on changes to our infrastructure and notify customers of material subprocessor changes as part of our agreements.