Continuous Trust & Compliance Portal

SOC 2 & ISO/IEC 27001 Compliance

Aanwik Solutions designs XintoX with controls aligned to AICPA SOC 2 (Type I / Type II) Trust Services Criteria and ISO/IEC 27001:2022 Information Security Management Standards. XintoX has not yet completed a SOC 2 examination or ISO/IEC 27001 certification; contact us for our current security documentation.

SOC 2 Trust Services Criteria

AICPA Trust Services Criteria

Evaluates policies, procedures, and architectural controls across the five trust principles governing SaaS context engines:

  • Security (CC1–CC9): Role-based access, rate-limiting, and single-device hardware locks.
  • Availability (A1.1–A1.3): Health telemetry probes, automatic MariaDB & Redis failover.
  • Processing Integrity (PI1.1): Tree-sitter AST verification of symbol locations to reduce hallucinations.
  • Confidentiality (C1.1): Multi-tenant database shards and zero raw code persistence.
  • Privacy (P1.1): Automatic secret and PII stripping in all audit streams.

ISO/IEC 27001:2022

Annex A Security Controls

Standardized Information Security Management System (ISMS) across organizational, technical, and physical layers:

  • A.5 Organizational Controls: Strict change governance, supplier management, and security policies.
  • A.8.10 Information Deletion: Right to be Forgotten API with complete multi-tier data disposal.
  • A.8.15 Audit Logging: Immutable tamper-evident audit records for every security action.
  • A.8.20 Network Security: HSTS enforcement, strict CSP, and transport isolation.
  • A.8.24 Cryptography: AES-256 encryption at rest, SHA-256 API key hashing.

Immutable Audit Trails (SOC 2 CC7.2 / ISO A.8.15)

Every critical event—including logins, API key generation, device binding, role assignment, and tier modifications—is committed to an append-only MariaDB log table with automated secret redaction.

Inspect Audit Log
Automated Redaction
Passwords, API keys, tokens, and authorization headers are scrubbed before persistence.
Actor Attribution
Every log contains IP address, user agent, actor role, and user ID timestamp.
Google Chat Alerts
High-severity changes trigger real-time webhooks into your dedicated security space.

Right to be Forgotten (ISO 27001 A.8.10 & GDPR / CCPA)

In accordance with international privacy mandates, organization owners have unilateral authority to execute irrevocable data disposal. When triggered, XintoX executes a synchronized purge:

1. Elasticsearch Indices

AST symbols, routes, schemas, and historical interaction indices are deleted.

2. Redis Caches

Tenant cached coding standards, rule overrides, and fast-path items are purged.

3. MariaDB Relational Data

All user accounts, API keys, usage metrics, and project metadata are cascaded.

Subprocessor Transparency Directory

SubprocessorService ProvidedData LocationCompliance Certifications
Hostinger Tier-3 DatacenterDedicated Virtual Servers, Compute & Volume StorageLithuania / European UnionISO/IEC 27001, Tier III Certified
Razorpay Software Pvt LtdPayment Processing & RBI-Compliant TokenizationIndia (Data Localization Compliant)PCI-DSS Level 1, ISO 27001, SOC 2
Google Cloud PlatformEnterprise Team Notifications & Webhook RelaysUnited States / GlobalSOC 1/2/3, ISO 27001, ISO 27017, ISO 27018

Require an Enterprise Vendor Security Assessment Questionnaire (VSAQ) or custom DPA?

Contact Compliance Engineering (compliance@aanwik.com)