Argorix
Argorix|Trust Center

Welcome to the Argorix Trust Center — a centralized hub for our commitment to security, privacy, and compliance. Here you will find transparent, up-to-date information about our security practices, the controls we operate, our subprocessors, and the documentation available to customers and prospects.

Contact Security

Compliance

ISO
27001
ISO 27001:2022
Controls aligned · certification roadmap
SOC 2
Type II
SOC 2 Type II
Controls aligned · certification roadmap
NIST
AI RMF
NIST AI RMF
Framework aligned
OWASP
LLM
OWASP LLM Top 10
Covered by platform controls

Our control framework is designed against ISO 27001:2022 and the SOC 2 trust services criteria. Third-party certification reports will be published in this Trust Center as soon as they are available.

Controls View More ›

Product Security | (7 Controls)

  • Secure Software Development Lifecycle established
  • Penetration Testing conducted
  • Change Management procedures enforced
  • Vulnerability scanning procedures established

Access Management | (9 Controls)

  • Role Based Access Control (RBAC) established
  • Multi Factor Authentication implemented
  • User Access Reviews conducted
  • Password policy enforced

Security and Continuity Procedures | (7 Controls)

  • Business Continuity and Disaster Recovery plans established
  • Continuity and Disaster Recovery plans tested
  • Incident Response plan tested
  • Data backups and restoration procedures tested

Data Security | (4 Controls)

  • Encryption at rest implemented
  • Encryption in transit implemented
  • Encryption key management process established
  • Network and firewall access restricted

How we earn trust

01

We govern AI the way we ask you to

Argorix runs its own AI systems under the same discovery, guardrails, and red-team validation we provide to customers.

02

Evidence over claims

Security posture should be demonstrable. Everything Argorix enforces produces traceable evidence you can inspect.

03

You stay in control

Deployment model, data residency, and access policy are your decisions — Argorix adapts to your environment.

Controls

Product Security | (7 Controls)

Secure Software Development Lifecycle established

Security is embedded across the full development lifecycle - from design and code review to deployment and maintenance - so vulnerabilities are prevented rather than patched late.

Penetration Testing conducted

Third-party penetration tests simulate real attacks against our systems. Findings are triaged and remediation of critical issues is tracked to closure; a summary report is available under NDA.

Change Management procedures enforced

All software and infrastructure changes are reviewed, approved, and traceable before reaching production, linking each change to its request and review trail.

Vulnerability scanning procedures established

Application and host scans run against known CVEs on a recurring schedule. Critical and high findings are tracked until remediated under our vulnerability management process.

Secure product architecture defined

The production architecture and its components are documented and reviewed so that security boundaries, data flows, and trust zones are explicit.

Production environment segregation enforced

Production is segregated from development and staging environments, reducing the risk of unauthorized access or unintended changes to live systems.

Intrusion Detection systems utilized

Network and host activity is continuously monitored for anomalous behavior, enabling early detection and rapid response to potential intrusions.

Access Management | (9 Controls)

Role Based Access Control (RBAC) established

Access is granted strictly by role through a central identity provider, and the role matrix is reviewed regularly to preserve least privilege.

Multi Factor Authentication implemented

MFA is required for privileged accounts and any access to sensitive systems, adding a second layer beyond credentials.

User Access Reviews conducted

Scheduled reviews validate that access to production systems, databases, and applications matches current job responsibilities; each review is documented and signed off.

Password policy enforced

A password policy defines required strength and rotation across systems, and compliance is monitored.

Restricted production access maintained

Only authorized users with a documented business need can reach the production environment.

Privilege access restricted

Privileged access to critical systems is limited to authorized personnel with a justified need, keeping sensitive operations tightly controlled.

Access control policies and procedures defined

Formal policy covers how access is provisioned, modified, and revoked, and how often reviews take place.

Production database access restricted

Production databases are reachable only by authorized personnel, and production data is not used in development or testing unless strictly necessary.

Access request and approval process defined

Access is provisioned only after a documented request tied to role and function is approved by a manager.

Security and Continuity Procedures | (7 Controls)

Business Continuity and Disaster Recovery plans established

Formal BC/DR plans define how services and infrastructure are restored after a disruption, including communication paths when key personnel are unavailable.

Continuity and Disaster Recovery plans tested

BC/DR plans are exercised periodically, including backup integrity checks and restoration drills.

Incident Response plan tested

The incident response plan is exercised at least annually; results feed updates that strengthen detection, escalation, and handling.

Data backups and restoration procedures tested

Production data is backed up regularly and stored separately from production; restorations are tested to confirm integrity and recoverability.

Production multi-availability zones utilized

Production workloads run across multiple availability zones for redundancy and high availability.

Production monitoring implemented

Performance, availability, and security signals are monitored continuously so issues are detected early and handled promptly.

Audit logging established

Key events - logons, deletions, errors, and changes to software or configuration - are logged across application and infrastructure layers and monitored.

Data Security | (4 Controls)

Encryption at rest implemented

Stored data is protected with industry-accepted encryption standards such as AES-256.

Encryption in transit implemented

Data in transit is protected with TLS 1.2 or newer; deprecated protocols are disabled.

Encryption key management process established

Encryption keys are handled under a defined process that restricts access to authorized users with a valid business need.

Network and firewall access restricted

Firewalls limit unnecessary ports, protocols, and services, and rules are periodically reviewed and approved.

Organization Security | (10 Controls)

Risk Assessment and treatment established

A company-wide risk assessment runs at least annually with periodic follow-ups, evaluating threats, likelihood, and impact to define treatment and tolerance.

Vendor Risk Management established

New vendors are assessed before engagement and re-assessed periodically to catch emerging risks.

Asset Management maintained

Physical and virtual assets are inventoried with ownership, classification, and location, ensuring accountability for sensitive systems.

Security Awareness Training implemented

Employees complete security awareness training on hire and annually thereafter.

Secure Development LifeCycle (SDLC) Training implemented

Engineers receive recurring secure-development training aligned with the SDLC methodology and secure development policy.

Defined roles and responsibilities established

Security, availability, and confidentiality responsibilities are formally assigned through job descriptions and policy.

Service Level Agreement established

Service commitments and availability targets are defined contractually, with advance notice for planned maintenance.

Candidates screening checks

New hires and internal transfers are screened for qualifications and role suitability.

Confidentiality agreement acknowledged by employees

Every employee signs a confidentiality agreement during onboarding, covering company and customer information.

Coordinated responsible disclosure program

We welcome coordinated vulnerability reports at security@argorix.com and respond promptly to validated findings.

Endpoint Security | (4 Controls)

Endpoint Detection and Response established

EDR continuously monitors endpoints to detect and respond to threats.

Disk encryption enforced

Organizational devices enforce full-disk encryption (AES-256), including media that stores personal data.

Threat and Malware protection enforced

Endpoints run real-time detection, prevention, and removal of malicious software.

Endpoint Management policies established

Managed devices must meet baseline policy: strong passwords, anti-malware, and disk encryption.

AI Governance | (5 Controls)

Adversarial AI red-team validation of our own systems

Argorix runs the same adversarial red-team validation on its own AI systems that it provides to customers.

Runtime guardrails enforced on our own AI

Our internal AI runtime operates under the same guardrails and policy enforcement we ship in the platform.

AI system inventory maintained

We apply our own discovery to keep a live inventory of the models and agents we operate.

Data minimization with redaction at the source

We collect only what is needed to govern AI risk, and sensitive content is redacted at the source wherever detection allows.

On-premise deployment option

When residency or policy requires it, customers can deploy on-premise so AI telemetry never leaves their environment.

Need the full control matrix mapped to ISO 27001 / SOC 2 criteria? Request access to our security documentation.

Subprocessors

Argorix uses a deliberately small set of third-party providers. For on-premise deployments, customer AI telemetry stays entirely inside the customer environment and is not shared with any subprocessor.

SubprocessorPurposeLocation
V2Nets Web hosting infrastructure for argorix.com public sites and this Trust Center Chile
Google LLC Web font delivery (Google Fonts) on public websites United States

Last reviewed: August 1, 2026. We review this list on changes to our infrastructure and notify customers of material subprocessor changes as part of our agreements.

Reports and Documents

Argorix Company Brochure Platform overview, use cases, and deployment models.
Download
Security Overview Architecture, data handling, encryption, and deployment security.
Penetration Test Summary Latest third-party and internal offensive testing summary.
Vendor Security Questionnaire Completed CAIQ-style questionnaire for vendor assessments.
Certification Reports (ISO 27001 / SOC 2) Third-party audit reports.
Published when available