Home / Trust centre
Information security, answered before you ask.
Your Voice of the Customer data holds your customers’ words and your agents’ names. This page sets out how CX Index protects it, where it lives, and what stays in your control. It is written for the security and procurement review, so it is thorough on purpose.
Certified
ISO 27001:2022An ISO 27001 certified organisation since 2018. The current certificate is independently audited and valid until August 2027.
At a glance
The answers your security questionnaire will ask for.
Summarised here so your reviewer can check the shortlist in one pass. Each line is covered in more detail below.
| Certification | ISO 27001:2022, certified since 2018, current certificate valid until August 2027 |
|---|---|
| Hosting | Amazon Web Services, with data residency available in more than 20 regions |
| Encryption in transit | All data transmitted over HTTPS using TLS 1.2 |
| Encryption at rest | Production data classified, with personal and confidential information encrypted using industry standard protocols |
| Backups | Regular snapshots of production data and infrastructure, a backup of every customer database, and periodic restore testing |
| Access control | Least privilege, need to know, every request authorised and auditable |
| Customer controls | Role based access with granular permissions, self managed anonymisation rules, retention and deletion under your control |
| Data export | Full raw export from inside the platform, by API, or on request |
| Regulation | Supports GDPR, CASL, LGPD and PIPL |
| AI governance | Choice of LLM provider or your own model, permissioned data access, token monitoring and a full prompt audit log |
01 Certification and compliance
Audited to an international standard.
Data security and trust
ISO 27001 sets out the security controls we operate and is audited independently. It protects sensitive data and gives your reviewers a standard they already recognise.
Legal and regulatory alignment
Our controls align with GDPR and the requirements of regulated industries, so the programme can run in banking, insurance, healthcare and the public sector.
Risk management
Structured risk assessments and mitigation plans reduce the chance and the impact of a breach or cyberattack.
Continuous improvement
We review infrastructure and services against industry best practice and keep improving them. Certification is renewed through external audit.
Regulations we support
02 Hosting and residency
Your data, in the region you choose.
Hosted on Amazon Web Services
CX Index runs on AWS and is available in more than 20 regions, so data can stay within the jurisdiction your regulator or your policy requires. Multi region programmes can hold each region’s data separately.
Backups
Production data and infrastructure are snapshotted regularly to allow recovery from a disaster, and every customer database is backed up in addition. Restore procedures are tested periodically.
Storage
Production data is classified. Personally identifiable and other potentially confidential information is encrypted and not available outside the production system.
03 The data we hold
What is stored, and why.
Customer feedback
CX Index captures customer feedback. When it is integrated with your CRM or helpdesk, it can also store the metadata and conversations related to cases.
Customer service data
An agent’s name, staff ID or email address may be associated with feedback about the quality of the interaction they handled.
Interactions
You decide whether to upload or import data at all. We recommend against storing confidential information, and deletion, storage and retention stay fully in your control.
Contact
CX Index uses email to send staff notifications according to the settings you choose, and the surveys module can send customer surveys by email.
Data export
You can take a full raw export of everything stored in CX Index, from inside the platform, through the API, or on request. That includes staff and feedback records.
04 Protection and control
Locked down by us. Configured by you.
Encryption
All data in transit is sent over HTTPS using TLS 1.2. Data at rest is classified, and protected information is encrypted using industry standard protocols.
Access control
We operate least privilege. Access is granted on a need to know basis, and every request must be authorised and auditable.
Your permissions
Role based access down to granular permissions, including rules for your own security settings and which attributes each role can see.
Anonymisation
Self managed anonymisation rules, so regulated teams can keep full reporting scope without exposing personal data.
Audit trail
User activity is recorded and reviewable, so every change to the programme has a name and a time against it.
Secure integration
Secure API and SFTP for data exchange, and audience exclusion lists to keep specified people out of every survey.
05 AI governance
The controls that get AI approved.
Your model, or ours
Choose from multiple LLM providers or bring your own, so your existing AI policy covers your customer data.
Permissioned access
Decide exactly which data AI features can read, and which roles can use them.
Prompt audit log
Every prompt is logged, so any AI generated insight can be traced back to what was asked.
Usage monitoring
Token monitoring shows how AI is being used and what it costs, before the invoice does.
Documents
Everything your reviewer will ask for.
Questions
Frequently asked questions.
Is CX Index ISO 27001 certified?
Yes. CX Index is ISO 27001:2022 certified, has been certified since 2018, and the current certificate is valid until August 2027.
Where is CX Index data hosted?
On Amazon Web Services, with data residency available in more than 20 regions.
Can we export our data?
Yes. You can take a full raw export from inside the platform, through the API, or on request.
Which privacy regulations does CX Index support?
GDPR, CASL, LGPD and PIPL.
Security review
One security review, against an estate that already passed one.
CX Index is built natively on Genesys Cloud CX and installed from the AppFoundry. Send us your questionnaire and we will turn it round alongside the commercial conversation, not after it.
