1.Scope of this statement
- 1.1This statement covers CEDX Systems Limited and its subsidiaries in Germany, the United States, Singapore and Canada, and every product delivered from the CEDX platform.
- 1.2A certification is claimed only where a current, unqualified assessment by an accredited body is held. Where scope is partial, the boundary is stated in clause 2 rather than left to inference.
- 1.3Beta and preview capabilities are outside the scope of every certification listed here until they reach general availability and have been through a full assessment cycle. They must not be used for production workloads.
- 1.4This statement is reviewed at least twice a year and immediately after any change to a certification's scope or status. The version number changes with each revision.
- 1.5Nothing in this statement is a warranty. The contractual position is set out in clause 11 of the terms of service and in the data processing agreement.
2.Certifications and attestations
| Standard | Scope | Assessed by | Last assessed |
|---|---|---|---|
| ISO/IEC 27001:2022 | The information security management system covering the platform, all products in general availability, and the operations of all five group entities. | Ardwick Certification Ltd, UKAS accredited | Recertified 4 February 2026; valid to 3 February 2029 |
| ISO/IEC 27017:2015 | Cloud-specific controls, as an extension to the 27001 scope. | Ardwick Certification Ltd | 4 February 2026 |
| ISO/IEC 27018:2019 | Protection of personal data in public cloud, as an extension to the 27001 scope. | Ardwick Certification Ltd | 4 February 2026 |
| ISO 22301:2019 | Business continuity management for the platform control plane and all eleven regions. | Ardwick Certification Ltd | 18 September 2025 |
| SOC 2 Type II | Security, availability and confidentiality trust services criteria, covering the platform and every product in general availability. Processing integrity is included for CEDX Ledger only. | Halloway Bracken LLP | Twelve months to 31 March 2026, unqualified opinion |
| SOC 1 Type II | Controls relevant to customers' financial reporting, covering CEDX Ledger and CEDX Store only. | Halloway Bracken LLP | Twelve months to 31 March 2026, unqualified opinion |
| PCI DSS v4.0 | Level 1 Service Provider, limited to the payment components of CEDX Ledger and CEDX Store. Cardholder data is tokenised at the point of capture and is not held in the wider platform. | Arclight Payments Ltd, as qualified security assessor | Attestation of compliance dated 29 January 2026 |
| Cyber Essentials Plus | United Kingdom corporate estate and endpoint fleet. | Marchmont Assurance Ltd | 11 November 2025 |
| CSA STAR Level 2 | Cloud Controls Matrix v4, assessed alongside the ISO/IEC 27001 audit. | Ardwick Certification Ltd | 4 February 2026 |
CEDX does not hold FedRAMP authorisation and does not claim it. Customers with United States federal requirements should assume the platform is not authorised for that use.
3.Data protection regimes
- 3.1CEDX complies with the UK General Data Protection Regulation and the Data Protection Act 2018 as a controller for its own business data, and as a processor for customer data. It is registered with the Information Commissioner's Office under registration ZA418826.
- 3.2CEDX complies with Regulation (EU) 2016/679 in respect of processing within the European Union. CEDX Systems GmbH is the appointed Article 27 representative and the Hessian Commissioner for Data Protection is the lead supervisory authority.
- 3.3A Data Protection Officer is appointed under Article 37 and can be reached at privacy@cedxsystems.com. The role reports to the board rather than to the executive team and cannot be dismissed for performing it.
- 3.4CEDX supports customers subject to the California Consumer Privacy Act as amended by the California Privacy Rights Act. CEDX acts as a service provider under that Act, does not sell or share personal information, and does not retain, use or disclose it for any purpose other than performing the services.
- 3.5For customers subject to HIPAA, CEDX will enter into a business associate agreement covering CEDX Vault, CEDX People and CEDX qDesk only. No other product is in scope and none should be used for protected health information.
- 3.6Transfers out of the United Kingdom or the European Economic Area are made under the International Data Transfer Agreement, or under the Standard Contractual Clauses with the UK Addendum, supported by a documented transfer risk assessment reviewed annually.
4.Data residency and regional isolation
A customer selects a region on the order form and their data stays in it. Isolation is enforced by the platform rather than by policy, and is verified continuously rather than at audit time.
| Region | Location | Adequacy position | Available since |
|---|---|---|---|
| uk-lon | London, United Kingdom | Domestic | 2011 |
| eu-fra | Frankfurt, Germany | EU / UK adequacy | 2017 |
| eu-dub | Dublin, Ireland | EU / UK adequacy | 2019 |
| ch-zrh | Zurich, Switzerland | UK and EU adequacy decisions in force | 2022 |
| us-nyc | New York, United States | Standard Contractual Clauses | 2016 |
| ca-tor | Toronto, Canada | UK and EU adequacy decisions in force | 2018 |
| br-gru | São Paulo, Brazil | Standard Contractual Clauses | 2023 |
| sg-sin | Singapore | Standard Contractual Clauses | 2018 |
| jp-tyo | Tokyo, Japan | UK and EU adequacy decisions in force | 2021 |
| au-syd | Sydney, Australia | Standard Contractual Clauses | 2020 |
| in-bom | Mumbai, India | Standard Contractual Clauses | 2024 |
- 4.1Customer data, including backups and search indices, is confined to the selected region. Telemetry leaving the region is limited to identifiers and request metadata, with record contents redacted before transmission.
- 4.2Support access from another region is off by default. Where a customer enables follow-the-sun support, each cross-region access is time-bound, requires a recorded reason and appears in the customer's own audit trail.
- 4.3Regional isolation is tested continuously by automated probes that attempt cross-region and cross-tenant reads. A failure raises a severity one incident.
- 4.4A customer may migrate between regions once per subscription year at no charge. The migration is planned, rehearsed and reconciled in the same way as an inbound migration.
5.Security architecture
- 5.1Tenant isolation is enforced at the data layer rather than in application code. Every query carries a tenant context that the storage layer will not execute without, which makes a cross-tenant read a structural impossibility rather than a bug that has not happened yet.
- 5.2Data is encrypted in transit with TLS 1.3 and at rest with AES-256. Keys are held in FIPS 140-2 Level 3 hardware security modules within the customer's region and rotated annually. Enterprise subscriptions may supply and revoke their own keys.
- 5.3Field-level encryption is available for nominated fields in CEDX Vault, CEDX People and CEDX Ledger, with keys distinct from the tenant key.
- 5.4Access to the platform is zero-trust: no network position confers any privilege, every request is authenticated and authorised, and there are no standing administrative privileges in production.
- 5.5Segregation of duties is enforced in the platform, not by convention. The person who authors a change cannot approve it, the person who approves it cannot deploy it, and no single identity holds all three entitlements.
- 5.6Every administrative and data-access action is written to an immutable audit trail that CEDX personnel cannot alter or delete, retained for thirteen months, and readable by the customer through the platform.
6.Independent testing and coordinated disclosure
- 6.1An independent penetration test of the platform and a rotating selection of products is carried out at least annually, and additionally after any material architectural change. The current provider is Marchmont Assurance Ltd, engaged on a three-year rotation.
- 6.2A summary of the most recent test, including the severity distribution of findings and the remediation status of each, is available to customers under a mutual non-disclosure agreement.
- 6.3Findings are remediated to a fixed timetable: critical within seven days, high within thirty, medium within ninety. Remediation is verified by retest rather than by assertion.
- 6.4CEDX operates a coordinated disclosure process. Reports go to security@cedxsystems.com, are acknowledged within twenty-four hours, and receive a substantive assessment within five Working Days.
- 6.5CEDX will not pursue or support legal action against a researcher who reports in good faith, confines testing to a tenant they control, makes no attempt to access another party's data, does not degrade the service for others, and allows ninety days before publishing.
- 6.6CEDX does not require a researcher to sign a non-disclosure agreement as a condition of reporting, and does not treat disclosure after the ninety-day period as a breach of these terms.
7.Availability, resilience and continuity
- 7.1The contractual availability target is 99.9 per cent per calendar month for standard subscriptions and 99.95 per cent where an enhanced service level has been purchased. Measured availability across the trailing twelve months was 99.99 per cent.
- 7.2Availability is measured in one-minute samples at the control plane and at each product, by the same instrumentation that pages the on-call engineer. Monthly figures are published on the status page whether they meet the target or not.
- 7.3Each region is deployed across at least three availability zones. The recovery point objective is five minutes and the recovery time objective is two hours; restoration from backup is tested quarterly and the result recorded.
- 7.4The business continuity management system is certified to ISO 22301. Continuity plans are exercised twice a year, once as a tabletop exercise and once as a live failover of a production region.
- 7.5Incidents at severity two and above receive a written root cause analysis within five Working Days, published to affected customers. Analyses attribute cause to a system, a process or a decision, and every one produces a tracked corrective action.
- 7.6Source code and deployment configuration for every product in general availability are held with an independent escrow agent. Enterprise customers may become beneficiaries at no charge; release conditions are set out in the escrow agreement.
8.Personnel and supplier controls
- 8.1All personnel are background screened before being granted access to production systems, to a standard appropriate to the role and lawful in the jurisdiction. Screening is repeated every three years for those holding elevated entitlements.
- 8.2Security and data protection training is completed on joining and annually thereafter. Completion is tracked and access is withdrawn where training lapses by more than thirty days.
- 8.3Access is reviewed quarterly by the entitlement owner rather than by a central team, and the review produces evidence automatically rather than by request.
- 8.4Joiner, mover and leaver processes are automated through CEDX People and CEDX Gate. Access is revoked within fifteen minutes of a leaver record being confirmed.
- 8.5Every supplier with access to customer data is assessed before engagement and at least annually thereafter, as described in clause 9 of the sub-processors page.
9.Accessibility and other obligations
- 9.1Products in general availability are built to meet the Web Content Accessibility Guidelines 2.2 at level AA. Conformance is assessed by an independent audit annually, and a Voluntary Product Accessibility Template is maintained for each product.
- 9.2Known conformance gaps are published with a remediation date rather than omitted. The current list is available on request to accessibility@cedxsystems.com.
- 9.3CEDX publishes a modern slavery statement each financial year under section 54 of the Modern Slavery Act 2015, approved by the board.
- 9.4CEDX publishes United Kingdom gender pay gap figures annually, and reports Scope 1, 2 and 3 emissions in its annual report.
- 9.5CEDX maintains a whistleblowing channel operated by an independent third party, available to employees, contractors, suppliers and customers.
10.Requesting evidence
- 10.1Certificates for ISO/IEC 27001, 27017, 27018 and 22301, and the PCI attestation of compliance, are provided on request without a non-disclosure agreement.
- 10.2SOC 1 and SOC 2 reports, penetration test summaries, the business continuity exercise report and due diligence summaries for sub-processors are provided under a mutual non-disclosure agreement, usually within two Working Days.
- 10.3A completed standard assessment pack, covering the Standardised Information Gathering questionnaire and the Cloud Controls Matrix, is maintained and issued on request. Most customer questionnaires are answered in full by that pack.
- 10.4Bespoke questionnaires are completed where the standard pack genuinely does not cover the question. Requests go to compliance@cedxsystems.com and are turned around within ten Working Days.
- 10.5Customers may exercise the audit rights in clause 12 of the data processing agreement whether or not they have requested any of the evidence described here.
11.Reporting a concern
- 11.1Suspected vulnerabilities go to security@cedxsystems.com, monitored around the clock. The PGP fingerprint is 4F2A 91C6 03BE 77D1 8E45 2210 9AC3 6E88 15DF 4B02.
- 11.2Suspected breaches of data protection law go to privacy@cedxsystems.com, which reaches the Data Protection Officer directly.
- 11.3Concerns about the accuracy of anything in this statement go to compliance@cedxsystems.com. Where a claim made on this site turns out to be wrong, the correction is made here first and the marketing pages are corrected afterwards.
- 11.4Ethical concerns, including anything a person would rather raise anonymously, go to the independent whistleblowing channel published in the supplier and employee handbooks.