Cybersecurity & Data Protection Policy
This policy is incorporated into the XGRC® SaaS Agreement by reference (in part) and documents Strategix’s security controls and data protection approach.
1. Security Governance
Strategix maintains an information security management programme aligned to ISO 27001:2022 and generally accepted industry practices. Our programme includes documented policies, defined roles and responsibilities, regular risk assessments, and ongoing monitoring and improvement.
2. Platform Security
- Access Control — Role-based access management, principle of least privilege, and multi-factor authentication for administrative access.
- Logical Segregation — Multi-tenant architecture with strict data isolation between customers.
- Encryption — Data encrypted in transit (TLS 1.2+) and at rest using industry-standard algorithms.
- Monitoring and Logging — Security event monitoring, audit logging, and alerting.
- Vulnerability Management — Regular vulnerability scanning, patch management, and penetration testing.
- Change Management — Documented change control processes for all platform changes.
3. Operational Resilience
Strategix maintains business continuity and disaster recovery capabilities appropriate to the XGRC® platform service model, including regular data backups with tested recovery procedures; documented incident response procedures; and capacity management and performance monitoring.
4. Data Protection
Strategix supports customer compliance by applying appropriate safeguards to Personal Information processed in connection with the Service; operating under the customer’s documented instructions in accordance with the Data Processing Addendum; and maintaining ISO 27001:2022 certification as evidence of our security posture.
5. Security Incidents
Confirmed security incidents affecting customer Personal Information are handled through documented response procedures and notified to affected customers in accordance with the Data Processing Addendum and applicable law.
6. Independent Assurance
Strategix maintains ISO 27001:2022 certification. On reasonable written request, Strategix will provide relevant certifications, audit summaries, or control statements, subject to confidentiality and security controls. On-site audits are not available as a standard offering; refer to the Data Processing Addendum for the applicable audit framework.
Need a security questionnaire completed, or a signed copy for procurement?
Contact us