Skip to content

Trust Center

How Woxox earns enterprise diligence

Security controls, compliance programme status, privacy links, and how to request attestations — without fake badges or invented uptime counters.

Controls

What ships in the Business OS

These are product capabilities buyers can validate in a security review — not marketing stickers.

Encryption

TLS in transit; AES-256 at rest. Customer-managed keys available for enterprise deployments.

Access control

RBAC with module- and field-level permissions. SSO/SAML and MFA on enterprise plans.

Audit logs

Searchable action history for governance, investigations, and customer diligence.

Tenant isolation

Logical multi-tenancy so organisations and workspaces stay separated by design.

Identity

One login across modules — shared sessions, roles, and workspace membership.

API & integrations

Scoped API access and webhooks so you can extend without bypassing controls.

Compliance

Programme aligned to common frameworks

Controls are designed with SOC 2, ISO 27001, GDPR, and HIPAA expectations in mind. Current attestation packages are shared with qualified buyers under NDA — this page is not a public report download.

What we share in diligence

  • Security questionnaire responses
  • Architecture and data-flow overview
  • Sub-processor list (on request)
  • DPA and privacy documentation

What we do not invent

  • No fake certification badges on the homepage
  • No public PDF of reports that are not yet available
  • No claim that every vertical is already certified
  • See Enterprise compliance for deployment context

Privacy

Data handling and resident rights

Legal policies live on dedicated pages. Use them for processing details; use this Trust Center for how to engage security and privacy together.

Availability

Uptime is a design goal — not a live status widget

We target enterprise-grade availability for production workspaces. We do not publish a fabricated public status dashboard with invented historical percentages.

Goal

99.99%

Enterprise uptime objective for core services — contractual SLAs are plan-specific.

Incident communication

Affected customers are notified through support and account channels. Ask sales for the current incident process during diligence.

Roadmap

A public status page and published sub-processor list workflow are on the product roadmap — see Roadmap.

Next step

Request trust materials

Qualified opportunities can receive questionnaire packs, DPA, and attestation status under NDA. Start with a demo or email so we can scope the right package.

Prefer email? info@woxox.com — mention “Trust materials” in the subject.

Woxox Business OS

Run a security walkthrough on the Business OS

See tenant isolation, roles, and audit trails in a live workspace — then request the paperwork that matches your diligence checklist.