SOC 2 & ISO/IEC 27001 Compliance
Aanwik Solutions designs XintoX with controls aligned to AICPA SOC 2 (Type I / Type II) Trust Services Criteria and ISO/IEC 27001:2022 Information Security Management Standards. XintoX has not yet completed a SOC 2 examination or ISO/IEC 27001 certification; contact us for our current security documentation.
SOC 2 Trust Services Criteria
AICPA Trust Services CriteriaEvaluates policies, procedures, and architectural controls across the five trust principles governing SaaS context engines:
- Security (CC1–CC9): Role-based access, rate-limiting, and single-device hardware locks.
- Availability (A1.1–A1.3): Health telemetry probes, automatic MariaDB & Redis failover.
- Processing Integrity (PI1.1): Tree-sitter AST verification of symbol locations to reduce hallucinations.
- Confidentiality (C1.1): Multi-tenant database shards and zero raw code persistence.
- Privacy (P1.1): Automatic secret and PII stripping in all audit streams.
ISO/IEC 27001:2022
Annex A Security ControlsStandardized Information Security Management System (ISMS) across organizational, technical, and physical layers:
- A.5 Organizational Controls: Strict change governance, supplier management, and security policies.
- A.8.10 Information Deletion: Right to be Forgotten API with complete multi-tier data disposal.
- A.8.15 Audit Logging: Immutable tamper-evident audit records for every security action.
- A.8.20 Network Security: HSTS enforcement, strict CSP, and transport isolation.
- A.8.24 Cryptography: AES-256 encryption at rest, SHA-256 API key hashing.
Immutable Audit Trails (SOC 2 CC7.2 / ISO A.8.15)
Every critical event—including logins, API key generation, device binding, role assignment, and tier modifications—is committed to an append-only MariaDB log table with automated secret redaction.
Right to be Forgotten (ISO 27001 A.8.10 & GDPR / CCPA)
In accordance with international privacy mandates, organization owners have unilateral authority to execute irrevocable data disposal. When triggered, XintoX executes a synchronized purge:
AST symbols, routes, schemas, and historical interaction indices are deleted.
Tenant cached coding standards, rule overrides, and fast-path items are purged.
All user accounts, API keys, usage metrics, and project metadata are cascaded.
Subprocessor Transparency Directory
| Subprocessor | Service Provided | Data Location | Compliance Certifications |
|---|---|---|---|
| Hostinger Tier-3 Datacenter | Dedicated Virtual Servers, Compute & Volume Storage | Lithuania / European Union | ISO/IEC 27001, Tier III Certified |
| Razorpay Software Pvt Ltd | Payment Processing & RBI-Compliant Tokenization | India (Data Localization Compliant) | PCI-DSS Level 1, ISO 27001, SOC 2 |
| Google Cloud Platform | Enterprise Team Notifications & Webhook Relays | United States / Global | SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018 |
Require an Enterprise Vendor Security Assessment Questionnaire (VSAQ) or custom DPA?
Contact Compliance Engineering (compliance@aanwik.com)