Trust Center
How Woxox earns enterprise diligence
Security controls, compliance programme status, privacy links, and how to request attestations — without fake badges or invented uptime counters.
Controls
What ships in the Business OS
These are product capabilities buyers can validate in a security review — not marketing stickers.
Encryption
TLS in transit; AES-256 at rest. Customer-managed keys available for enterprise deployments.
Access control
RBAC with module- and field-level permissions. SSO/SAML and MFA on enterprise plans.
Audit logs
Searchable action history for governance, investigations, and customer diligence.
Tenant isolation
Logical multi-tenancy so organisations and workspaces stay separated by design.
Identity
One login across modules — shared sessions, roles, and workspace membership.
API & integrations
Scoped API access and webhooks so you can extend without bypassing controls.
Compliance
Programme aligned to common frameworks
Controls are designed with SOC 2, ISO 27001, GDPR, and HIPAA expectations in mind. Current attestation packages are shared with qualified buyers under NDA — this page is not a public report download.
What we share in diligence
- Security questionnaire responses
- Architecture and data-flow overview
- Sub-processor list (on request)
- DPA and privacy documentation
What we do not invent
- No fake certification badges on the homepage
- No public PDF of reports that are not yet available
- No claim that every vertical is already certified
- See Enterprise compliance for deployment context
Privacy
Data handling and resident rights
Legal policies live on dedicated pages. Use them for processing details; use this Trust Center for how to engage security and privacy together.
Availability
Uptime is a design goal — not a live status widget
We target enterprise-grade availability for production workspaces. We do not publish a fabricated public status dashboard with invented historical percentages.
Goal
99.99%
Enterprise uptime objective for core services — contractual SLAs are plan-specific.
Incident communication
Affected customers are notified through support and account channels. Ask sales for the current incident process during diligence.
Roadmap
A public status page and published sub-processor list workflow are on the product roadmap — see Roadmap.
Next step
Request trust materials
Qualified opportunities can receive questionnaire packs, DPA, and attestation status under NDA. Start with a demo or email so we can scope the right package.
Prefer email? info@woxox.com — mention “Trust materials” in the subject.
Woxox Business OS
Run a security walkthrough on the Business OS
See tenant isolation, roles, and audit trails in a live workspace — then request the paperwork that matches your diligence checklist.