Trust & Compliance

Compliance Built for
Regulated Enterprise AI

KXN is the only enterprise Agentic AI platform with ISO 42001 certification, SOC 2 Type II audit, HIPAA readiness, and full GDPR compliance — before you sign a contract.

ISO 42001

AI Management System

Certified

ISO/IEC 42001:2023 is the first international standard for AI Management Systems. KXN is certified against this standard, demonstrating a systematic approach to responsible AI development, deployment, and monitoring.

  • AI risk assessment and treatment process
  • Documented AI ethics and accountability framework
  • Regular third-party conformity assessments
  • Continuous improvement processes for AI systems
  • Governance structure with defined AI officer roles

Required by: financial services regulators, EU AI Act high-risk system operators, public sector AI procurement

SOC 2 Type II

Security, Availability & Confidentiality

Audited

Our SOC 2 Type II report covers the Trust Service Criteria for Security, Availability, and Confidentiality. The Type II audit tests controls over a 12-month observation period — not just a point-in-time assessment.

  • Annual independent audit by a licensed CPA firm
  • Controls tested over 12-month observation period
  • Covers security, availability, and confidentiality TSCs
  • Available under NDA to enterprise customers and prospects
  • Continuous control monitoring between audits

Required by: enterprise security teams, vendor risk management programs, Fortune 500 procurement

HIPAA Ready

Protected Health Information

Ready

KXN supports HIPAA-compliant deployments for healthcare customers. We sign Business Associate Agreements (BAAs) and our sovereign deployment model ensures PHI never leaves the customer's data perimeter.

  • Business Associate Agreements (BAAs) available
  • PHI never processed on shared infrastructure without BAA
  • Sovereign deployment option: agents run in your HIPAA environment
  • Audit logging of all PHI access events
  • Workforce training and breach notification procedures

Required by: hospitals, health systems, health insurance companies, pharma, medical device companies

GDPR Compliant

EU General Data Protection Regulation

Compliant

KXN processes EU personal data in compliance with GDPR. We act as a Data Processor for customer data and maintain a Data Processing Agreement (DPA) with all European customers.

  • Data Processing Agreements (DPAs) for all EU customers
  • Data residency options: EU-only infrastructure available
  • Article 32 technical and organizational measures documented
  • Data subject request handling process (access, deletion, portability)
  • Privacy by design embedded in AI system architecture

Required by: any enterprise processing EU personal data, companies with EU customers or employees

NIST AI RMF

AI Risk Management Framework

Aligned

KXN's AI governance program is aligned with NIST AI RMF 1.0. Our GOVERN, MAP, MEASURE, and MANAGE functions are documented and available to customers in our AI Risk Management documentation package.

  • GOVERN: AI risk governance structure and policies
  • MAP: AI use case risk categorization methodology
  • MEASURE: AI model performance and risk metrics
  • MANAGE: Incident response and model lifecycle management
  • AI RMF Playbook available to enterprise customers

Required by: US federal agencies, DoD contractors, NIST-aligned enterprise AI programs

EU AI Act Ready

High-Risk AI System Compliance

Ready

KXN's agentic AI platform is designed for EU AI Act compliance for high-risk AI system deployments. We provide technical documentation, conformity assessment support, and human oversight configuration required by the Act.

  • Technical documentation package (Annex IV compliant)
  • Human oversight mechanisms configurable per deployment
  • Incident and near-miss logging for regulators
  • Fundamental rights impact assessment support
  • Registration support for EU AI Act database (where required)

Required by: enterprises deploying AI in EU-regulated domains (HR, credit, healthcare, critical infrastructure)

Compliance FAQs

Can I request a copy of the SOC 2 Type II report?

Yes. Enterprise customers and qualified prospects can request the SOC 2 Type II report under a mutual NDA. Contact your KXN account representative or reach out via our contact form.

Do you sign Business Associate Agreements for HIPAA?

Yes. KXN executes BAAs with all healthcare customers before processing any PHI. We offer sovereign deployment options where agent inference runs entirely within your HIPAA-compliant infrastructure.

Where is customer data processed for GDPR purposes?

European customers can elect EU-only data processing. KXN operates EU infrastructure in Germany (Frankfurt) and Ireland. Standard deployments use EU infrastructure by default for EU customers.

What is ISO 42001 and why does it matter for AI?

ISO 42001 is the first international standard for AI Management Systems. It provides enterprises with assurance that KXN has systematic processes for responsible AI governance — including risk assessment, ethics oversight, and accountability structures. This matters most in regulated industries where "we have an AI policy" is insufficient.

How does KXN support EU AI Act compliance for our deployments?

KXN provides technical documentation, conformity assessment support, and configurable human oversight mechanisms required for high-risk AI system deployments under the EU AI Act. We work with your compliance team to complete required documentation and registration steps.

Need compliance documentation?

Request the SOC 2 report, DPA, BAA, or ISO 42001 certificate for your vendor risk assessment.