Security you can assess.
Evidence you can review.
Choose a security partner with a clear basis for trust. Review Moxso’s ISO 27001 certification, data-handling practices and hosting information, with supporting documentation for your security and procurement review.
Understand the standard.
Review the scope.
ISO 27001 certification covers our information security management system. Review it alongside the product capabilities and data-processing documentation relevant to your regulatory requirements.
Open the Trust Center
ISO 27001CertifiedInformation security management system
Moxso maintains an ISO 27001-certified information security management system. Review the certificate and its scope as part of your supplier assessment.
NIS2AlignedSecurity awareness and human risk
Review how training, simulations and risk reporting support your security awareness program and the evidence your organization needs.
DORAAlignedOperational resilience for financial services
Review employee training, simulation results and risk reporting as part of your organization’s operational resilience assessment.
GDPRDocumentedData processing agreement
Review the data processing agreement, subprocessor register and applicable transfer safeguards against your privacy requirements.
Cyber EssentialsReview scopeUK procurement requirements
If your procurement process requires Cyber Essentials or Cyber Essentials Plus, request the applicable evidence and confirm its scope during your review.
EU data sovereignty by architecture.
Data sovereignty depends on where data is hosted, who processes it and the safeguards that apply. Assess European hosting alongside subprocessor locations and contractual commitments to establish the scope your organization requires.
Moxso uses European hosting. Confirm the production and backup locations for your service as part of your procurement review.
Production in Paris with resilience architecture in Amsterdam. No non-EU regions in the customer data path.
Moxso protects personal data with encryption in transit and at rest, alongside access controls and audit logging.
Review the data processing agreement and applicable transfer safeguards against your EU residency and sovereignty requirements.
Support your assessment.
Understand the evidence.
Review your requirements for NIS2.
Assess Moxso against the standards and obligations relevant to your organization. Review certification, product records and contractual safeguards according to their scope.

Security awareness records
for your NIS2 review.
Use training, simulation and risk records to support your assessment of security awareness activities. Review how these capabilities fit your organization’s wider NIS2 program.
- Awareness — training activity and simulation responses
- Follow-up — records of risk-based interventions
- Progress — Human Resilience Score and risk trends
- Oversight — reporting across employees, teams and the organization

Human risk visibility
for resilience reviews.
Bring employee risk and security awareness records into your operational resilience review. Assess the service and its supporting documentation against your own DORA requirements.
- Supplier review — security and data-processing documentation
- Threat reporting — employee phishing reports and recorded outcomes
- Simulations — scenarios informed by role and threat context
- Governance — risk reporting with department and employee views

Certified information security.
Controls you can evaluate.
Moxso maintains ISO 27001-certified information security controls. Encryption, access controls, audit logging and regular penetration testing support the protection of personal data.
- Certification — review the certificate and applicable scope
- Data protection — encryption in transit and at rest
- Access and accountability — access controls and audit logging
- Security testing — regular penetration testing

Clear processing responsibilities.
Documented safeguards.
For customer platform data, Moxso acts as processor on the customer’s behalf. Review the data processing agreement and subprocessor register to understand processing responsibilities, locations and safeguards.
- Processing locations — review hosting and subprocessor scope
- Agreement — assess the DPA against your requirements
- Transfers — review applicable safeguards for processing outside the EU/EEA
- Data rights — requests are handled through the customer as controller
Understand the data.
Know the responsibilities.
Understand what information supports the service and how it is used. The privacy policy and data processing agreement provide the scope for your privacy and procurement review.
Data with a purpose.
Processing with context.
- Operational signalsDelivering the contracted service
Moxso processes customer platform data on the customer’s behalf to deliver the contracted service, including employee identity, training records and relevant risk signals.
- Behavioral dataUnderstanding employee risk
Role context, simulation responses and learning activity help the platform assess risk and guide relevant interventions.
- External exposureAdding external threat context
Credential exposure and open-source threat information add context to employee and team risk profiles.
Your data.
Clear responsibilities.
- Email contentReported. Not inspected.
We do not read employee email by default. Content enters only when a user reports a message or the platform runs a simulation.
- Customer data ownershipYours. Not ours.
Never sold, licensed, or shared. Benchmarking uses only aggregated, anonymized data that cannot identify anyone.
- TransparencyNo surprises in the fine print.
What enters, why, how it is processed, and where it is stored — all documented and reviewable via the Trust Center and DPA.
Give your review team
a clear starting point.
Bring security, privacy and procurement into the same review. Start with the Trust Center for security documentation, the data processing agreement and subprocessor information. Confirm the scope that applies to your service and any additional evidence your team requires.