Security and Data Protection for Your Supply Chain
We manage critical information from thousands of suppliers and millions in transactions. That's why our security architecture isn't an "extra" — it's the foundation of everything we do.
"Sleeping soundly is part of the service."
Last updated: August 2026
Our Protection Pillars
Strong Data Encryption
Your data travels protected. TLS 1.3 for data in transit. Documents uploaded by your suppliers are stored encrypted with AES-256; database and volume encryption is enabled per project, according to the client's policies. Passwords are stored hashed, and our support team only accesses your environment under your express, time-limited authorization.
Resilient Infrastructure
100% SaaS platform on Amazon Web Services (AWS), in the United States (Northern Virginia region), with redundancy across multiple availability zones. There is no on-premise model in our standard offering. We commit to a 99.6% availability SLA, with Multi-AZ deployment on AWS: if one server fails, another takes over automatically.
Continuous Monitoring
We monitor threats continuously with automated detection (AWS GuardDuty and CloudTrail). We block malicious traffic before it reaches the platform using a web application firewall (WAF) and anti-DDoS protection.
Regional Regulatory Compliance
We don't just protect bits — we protect your legal liability.
Colombia
Our platform supports the supplier know-your-vendor and due diligence processes required by our clients' Sagrilaft / Sarlaft / PTEE programs, and Egixia complies with the Colombian personal data protection regime (Law 1581 of 2012).
Mexico
Our data processing takes the LFPDPPP as a reference to facilitate compliance for our clients in Mexico.
Regional & Global
We apply good practices aligned with international privacy standards (such as GDPR and LGPD) on data minimization, security and data subject rights. Client-specific regulatory requirements are agreed in the service contract.
Audits & Certifications
Backed by certified AWS infrastructure and by periodic external security testing.
Certified infrastructure (AWS)
We run on Amazon Web Services infrastructure, certified under ISO 27001, SOC 1/2/3 and PCI DSS.
Bi-annual penetration testing
We engage independent external specialists to test our security twice a year. An executive report is available under NDA.
SOC 2 (aligned, not certified)
Our security, availability and confidentiality controls are structured taking the SOC 2 framework as a reference. We do not yet hold a SOC 2 Type II report; we will publish the update when one is available under NDA.
Security FAQ
Where is my data hosted, and under which infrastructure certifications?
100% SaaS platform on Amazon Web Services (AWS), in the United States (Northern Virginia region), with redundancy across multiple availability zones. We run on AWS infrastructure certified under ISO 27001, SOC 1/2/3 and PCI DSS. There is no on-premise or hybrid model in our standard offering. See also the International Data Transfer section of our Privacy Policy.
Is Egixia ISO 27001 certified, or does it hold a SOC 2 report?
No. Egixia is not ISO 27001 certified and does not hold an issued SOC 2 Type II report. What we do have is: certified AWS infrastructure (ISO 27001, SOC 1/2/3, PCI DSS) + our own controls aligned to ISO 27001 + external penetration testing with a report available under NDA. We will publish an update if and when we hold a certification of our own.
How is my data encrypted in transit and at rest?
TLS 1.3 for data in transit. Documents uploaded by your suppliers are stored encrypted with AES-256; database and volume encryption is enabled per project, according to the client's policies. Passwords are stored hashed.
How is my data isolated from other clients' data?
Per-client isolation: dedicated instance and database with logical segregation; each client operates on its own storage bucket, with access policies that prevent cross-client access.
Who has access to my information?
Your team controls access via roles and permissions. Our support staff only accesses under your express, time-limited authorization. Actions are recorded in audit logs, and the retention of those logs is enabled per project, according to the client's policies.
How do users authenticate? Do you support MFA and SSO with our corporate directory?
OAuth 2.0 / JWT authentication with role-based access control and configurable password policy. Multi-factor authentication is mandatory for administrative roles. General multi-factor authentication and corporate directory integration (Azure AD, Microsoft 365, Google Workspace, LDAP/SAML) are advanced features enabled per project.
Do the AI agents use my data to train models?
Data processed by the AI agents is not used to train models: it is a contractual guarantee that EGIXIA holds with its subprocessors, and they with their model providers. Each task runs in an isolated environment with no access to other clients' data, and EGIXIA performs proactive deletion within 72 hours of delivery, with a maximum retention of 14 days at the subprocessor. No output is applied without prior human review. Reversible pseudonymization of sensitive documents before processing, and the retention of client documents, are enabled per project, according to the client's policies.
How often is the platform tested by external security specialists?
We engage independent external specialists to test our security twice a year. An executive report is available under NDA.
What happens if there is a security incident?
We maintain a security incident response procedure that includes detection, containment, root-cause analysis and remediation. In the event of an incident affecting a client's data, we will notify the affected client without undue delay once the incident is confirmed, in accordance with the service agreement and applicable legal obligations (including reporting to the Colombian SIC where applicable).
How do I report a vulnerability?
security@egixia.com is the channel for reporting vulnerabilities and security incidents. Include a description of the finding, the steps to reproduce it, and your contact details.
What happens in a disaster?
We have a formalized Disaster Recovery Plan: 4-hour RTO and 24-hour RPO, with daily snapshots and automated database backups retained for 30 days.
Does Egixia certify my company under Sagrilaft, Sarlaft or PTEE?
No — these are different things. Platform security protects your information (encryption, access control, monitoring). Separately, the platform supports the supplier know-your-vendor and due diligence processes required by our clients' Sagrilaft / Sarlaft / PTEE programs; compliance with the program remains the responsibility of the client and its compliance officer. Client-specific regulatory requirements are agreed in the service contract.
Incident Management
We maintain a security incident response procedure that includes detection, containment, root-cause analysis and remediation. In the event of an incident affecting a client's data, we will notify the affected client without undue delay once the incident is confirmed, with the information available on its scope and the measures taken, in accordance with the service agreement and applicable legal obligations (including reporting to the Colombian SIC where applicable). To report a vulnerability or an incident: security@egixia.com.
Report an incident: security@egixia.com