Compliance

Compliant by Design

Axon AI operates under rigorous regulatory frameworks because our customers — hospitals, banks, and logistics enterprises — have no room for compliance failures.

Certifications

Our Regulatory Posture

CertificationScopeAuditor / BasisStatusReview Cycle
SOC 2 Type IISecurity, Availability, ConfidentialityIndependent accredited auditor
Current
Annual
ISO 27001Information Security Management SystemCertification body accredited by UKAS
Current
3-year surveillance
HIPAAProtected Health Information (USA)Internal controls + BAA available
Ready
Continuous
GDPR / UK GDPREU & UK personal data subjectsDPO oversight + SCCs in place
Current
Continuous
PCI-DSS Level 1Payment card data (Aetheris Voice integrations)Qualified Security Assessor (QSA)
Attestation on request
Annual
NHS DSPTNHS Data Security & Protection Toolkit (UK)NHS Digital self-assessed, evidence reviewed
Standards Met
Annual
Frameworks

Standards We Align To

NIST AI RMF

AI risk management applied at design, deployment, and monitoring stages.

OWASP LLM Top 10

Active controls against all 10 LLM application security risks.

EU AI Act (High-Risk)

Pre-emptive compliance posture for high-risk AI categories.

FHIR R4

Clinical data interoperability standard for all CareFlow integrations.

MiFID II

Financial instrument communications compliance for Aetheris Voice deployments.

To request a copy of our compliance documentation or vendor questionnaire, email [email protected].