Security and compliance, on the record.
Everything your procurement, security, or legal team needs to evaluate XGRC® Software — hosting, certifications, subprocessors, and data protection commitments.
Security & certification
XGRC® Software is certified to ISO 27001:2022 for information security management, covering the governance, risk assessment, controls and continuous improvement processes that protect customer data.
Read more →Data hosting & residency
XGRC® Software is hosted on Microsoft Azure in the West Europe (Netherlands) region. Azure's infrastructure holds its own ISO 27001, ISO 27017, ISO 27018 and SOC 2 Type II certifications.
Read more →Subprocessors
Our primary subprocessors are Microsoft Azure and Microsoft 365, used for hosting, infrastructure and productivity services. Customers receive advance written notice of any material subprocessor change, with the right to raise objections on data protection grounds.
Read more →Data protection
Customer personal data is processed under a Data Processing Addendum satisfying POPIA section 21 operator agreement requirements, with a 72-hour security incident notification commitment and defined data subject rights handling.
Read more →Privacy Policy, Cookie Policy & Website Terms.
Our full legal and policy documentation is published in the Legal Hub, including the Data Processing Addendum and SaaS-incorporated policies.
Need a security questionnaire completed, or a signed DPA?
Our team can provide security questionnaire responses, certification evidence, and signed data processing documentation for procurement review.
[email protected] · +27 (0)87 802 0179