Trust & Compliance

Built to be trusted with production systems.

This page is maintained by Dexra and summarises the certifications, partner accreditations and operational controls that underpin our delivery. For procurement packs, DPAs, penetration-test summaries or our latest SOC 2 status letter, request the trust pack.

Certifications & alignments

Standards we hold ourselves to.

Where a scheme is achieved, we say so. Where it's in-flight, we say that too — no "compliant with everything" theatre.

ISO/IEC 27001

Aligned — certification in progress

Information Security Management System modelled on ISO/IEC 27001:2022 controls, with an internal audit programme and management review cycle.

SOC 2 Type II

Readiness programme underway

Security, Availability and Confidentiality Trust Services Criteria covered by documented controls; observation window in progress with an independent CPA firm.

Cyber Essentials Plus

Certified

Certified against the UK NCSC Cyber Essentials Plus scheme — annually re-tested by an accredited assessor.

UK GDPR & EU GDPR

Compliant

Registered UK data controller. DPA, SCCs and UK IDTA available. Data residency in UK and EU regions supported by default.

Partner accreditations

Deep, verifiable relationships with the vendors we deploy.

Microsoft Solutions Partner

Designations across Digital & App Innovation and Data & AI on Azure.

AWS Advanced Tier Services Partner

Advanced tier with practices spanning Migration, DevOps and Machine Learning.

NVIDIA Preferred Solution Partner

Access to L40S, H100/H200 and Blackwell platforms plus NVIDIA AI Enterprise licensing.

Operational controls

The day-to-day practices behind the badges.

Certifications describe the frame. These are the controls Dexra operates every day across managed engagements.

Access & authentication

SSO with enforced MFA, short-lived credentials, hardware-key admin access, and quarterly access reviews across every environment we operate.

Data protection

TLS 1.3 in transit; AES-256 at rest across managed environments. Customer secrets held in customer-owned vaults; Dexra never brokers long-lived credentials.

Software supply chain

Signed builds, SBOM generation, image and dependency scanning in CI, and CIS-benchmarked base images for every workload we ship.

Operations & change control

Error-budget-driven change management, peer-reviewed IaC, immutable audit logs, and rehearsed rollback for every production deployment.

Incident response

24/7 on-call rota, defined severity ladder, customer notification within contracted SLA, and post-incident reviews shared in writing.

Business continuity

Documented RTO/RPO per workload, tested restores, and geographically diverse infrastructure for managed services.

About the content on this page

Certifications, alignments and partner statuses listed here are maintained by Dexra and reflect our current programme. They are not independently verified by the hosting or design platform. Report a suspected security issue to security@dexra.cloud.

Need our full trust pack?

DPA, SCCs, information security policy summary, pen-test attestation and current SOC 2 status letter — sent on request under NDA.

Request the pack