ISO/IEC 27001 Certified
Xirocco has achieved ISO/IEC 27001 certification, reinforcing our commitment to information security, risk management and operational resilience.
Security & GDPR
Xirocco is committed to protecting the confidentiality, integrity and availability of customer data.
Our platform is designed for organisations that require a secure, reliable and commercially serious service. We apply recognised security practices across product development, hosting, operations and supplier management, and continue to strengthen our controls as customer and regulatory expectations evolve.
Xirocco is hosted on Amazon Web Services (AWS), and our application is developed using secure coding practices aligned with OWASP standards.
Xirocco has achieved ISO/IEC 27001 certification, reinforcing our commitment to information security, risk management and operational resilience.
Customer data is hosted on AWS and remains resident in the United Kingdom. AWS operates a dedicated Europe (London) Region that supports UK-based data hosting.
Our application is developed using industry-standard secure coding practices and OWASP-aligned standards. Security is considered throughout development and operation rather than treated as a separate activity after implementation.
Customer data is not used to train general-purpose AI models.
Any AI capability within the platform is intended to operate on customer-authorised data for that customer's own use, rather than being used to improve shared foundation models or train third-party systems.
Xirocco is committed to handling personal data responsibly and in accordance with applicable UK data protection law. Our approach is aligned with:
UK GDPR
Data Protection Act 2018
We apply the same seriousness to privacy as we do to information security. This includes:
Being clear about how data is handled
Limiting processing to legitimate business purposes
Applying appropriate technical and organisational safeguards
Expecting equivalent standards from relevant suppliers and service providers
Protecting personal data against unauthorised access, loss, misuse, alteration or disclosure
Further information about how Xirocco processes personal data is available in our Privacy Policy.
Across our services, Xirocco is committed to:
Protecting customer data through appropriate technical and organisational measures
Keeping UK and EU customer data hosted in the United Kingdom
Maintaining defined continuity and recovery arrangements
Applying secure development practices
Continuing to improve security controls over time
Supporting customer security, privacy, procurement and legal due diligence
Not using customer data to train general-purpose AI models
Handling personal data in accordance with UK GDPR and the Data Protection Act 2018
Maintaining registration with the UK Information Commissioner's Office
ICO registration number:
ZB178559
Xirocco uses Amazon Web Services for hosting. AWS provides infrastructure and compliance resources that support the operation of secure cloud services, including:
UK-based hosting through the AWS Europe (London) Region
Data protection and privacy controls
Encryption capabilities
Identity and access management
Logging and monitoring capabilities
Business continuity and resilience features
Compliance documentation and audit artefacts
Where AWS acts as a service provider to Xirocco, relevant contractual and data-processing arrangements apply. Use of AWS forms part of Xirocco's wider security architecture and does not, by itself, replace Xirocco's own responsibilities for security, privacy, governance or compliance.
We aim to apply security throughout the lifecycle of Xirocco Strategy Suite. This includes:
Secure application development
Appropriate access controls
Protection of customer information
Controlled use of infrastructure and services
Security monitoring
Supplier management
Operational safeguards
Business continuity and recovery planning
Ongoing review and improvement
Our development practices are aligned with recognised OWASP secure-development principles.
Xirocco does not use customer data to train general-purpose AI models. Where AI capabilities are used within Xirocco or Maeros AI, they are intended to operate on data authorised for use by the relevant customer. Customer information is used to support that customer's own analysis and decision-making rather than to train shared models for use by unrelated organisations.
Human judgement remains central to the use of Xirocco Strategy Suite and Maeros AI.
Depending on the nature of the engagement and the information being processed, Xirocco may act as a data controller or a data processor.
Where Xirocco processes customer data on behalf of a customer, the customer will generally remain the controller and Xirocco will process that information in accordance with the relevant contractual arrangements.
Where Xirocco determines the purposes and means of processing personal data, it acts as the controller. Further details are set out in the Xirocco Privacy Policy.
Xirocco uses selected service providers to support the operation of its business and technology services. Relevant suppliers are expected to handle information appropriately and only for authorised purposes. Security, privacy and data protection considerations form part of our approach to supplier management and due diligence.
We regularly support customer security, privacy, procurement and legal review processes. If your organisation is carrying out:
Security due diligence
Supplier assurance
Vendor assessment
Privacy review
Procurement assessment
Legal review
Technology risk assessment
we can provide relevant information to support that process.
Questions about this page, requests relating to it and relevant concerns can be submitted through the Contact page.
Start a Conversation
Share what is on your agenda and we'll explore, without obligation, whether we can help.