Security & GDPR

Security, Privacy & Data Protection

Last updated: April 2026

Xirocco is committed to protecting the confidentiality, integrity, and availability of customer data.

Our platform is designed for organisations that need a secure, reliable, and commercially serious SaaS service. We apply recognised security practices across product development, hosting, operations, and supplier management, and we continue to strengthen our controls as customer and regulatory expectations evolve. Xirocco is hosted on Amazon Web Services (AWS), and our application is developed using secure coding practices aligned to OWASP standards.

Security at a glance

ISO/IEC 27001 Certified

Xirocco has achieved ISO/IEC 27001 certification, reinforcing our commitment to enterprise-grade information security, risk management, and operational resilience.

UK Data Residency

Customer data is hosted in AWS and remains fully resident in the UK. AWS operates a dedicated Europe (London) Region, which supports UK-based data hosting requirements. (AWS Documentation)

Business Continuity & Disaster Recovery

Xirocco’s business continuity and disaster recovery arrangements include resilience in Ireland, helping support service continuity and recovery planning.

Secure Cloud Infrastructure

We use AWS as our cloud hosting provider because it offers a highly scalable and secure cloud environment. For customers who want to review AWS’s own security, compliance, and privacy documentation, the following official resources are helpful:

AWS security, compliance and privacy resources

  • AWS Compliance Programs — overview of AWS compliance frameworks, attestations, certifications, and assurance programmes. ( Amazon Web Services, Inc.)
  • Introduction to AWS Security: Compliance — AWS explanation of how compliance works in the shared responsibility model. ( AWS Documentation)
  • AWS Compliance FAQ — practical answers on reports, certifications, SOC reports, and AWS Artifact. ( Amazon Web Services, Inc.)
  • AWS Artifact — access point for AWS compliance reports and audit artefacts, referenced by AWS in its compliance materials. ( AWS Documentation)
  • AWS GDPR Center — AWS guidance on GDPR and UK GDPR, including processor commitments. ( Amazon Web Services, Inc.)
  • AWS Data Processing Addendum (DPA) — AWS information on its DPA and how it applies automatically where required. ( AWS Documentation)
  • AWS Data Protection and Privacy — AWS overview of privacy, encryption, access control, logging, and related protections. ( Amazon Web Services, Inc.)

Secure Development Practices

Our application is developed using industry-standard secure coding practices and OWASP-aligned standards.

AI Data Protection

Customer data is not used to train general-purpose AI models. Any AI capability within the platform is intended to operate on customer-authorised data for the customer’s own use, not to improve shared foundation models or train third-party systems.

Privacy & Data Protection

Xirocco is committed to handling personal data responsibly and in line with applicable UK data protection law. Our approach is aligned to the UK GDPR and the Data Protection Act 2018, which together form the core legal framework for personal data protection in the UK. (ICO)

We act with the same seriousness on privacy as we do on security. That means being clear about how data is handled, limiting processing to legitimate business purposes, applying appropriate safeguards, and expecting equivalent standards from relevant suppliers and service providers.

Our Commitments

We are committed to the following principles across our service:

  • protecting customer data through appropriate technical and organisational measures;
  • keeping UK and EU customer data hosted in the UK;
  • maintaining defined continuity and recovery arrangements;
  • applying secure development practices and ongoing security improvement;
  • supporting customer due diligence and procurement reviews;
  • not using customer data to train general AI models;
  • handling personal data in line with UK GDPR and the Data Protection Act 2018; and
  • maintaining registration with the UK Information Commissioner’s Office (ICO - registration number ZB178559)

Due Diligence

We regularly support customer security, privacy, procurement, and legal review processes. If you are completing due diligence, vendor assessment, or procurement documentation, please contact us and we will help you with the relevant information.

If you have any questions about security, privacy, or GDPR, please contact info@xirocco.io

Modern business leaders are asking whether the organisation is ready for what comes next, and what the exposure is if it is not.

Xirocco empowers IT leaders to respond confidently to the questions CEOs, CFOs, COOs and business leaders raise every day. It delivers clear, defensible answers to the organisation’s most strategic priorities, grounded in evidence - not in gut feel, intuition, or vendor opinions.