Compliance

What certifications do you hold?

In short

SOC 2 Type II in progress, on a published timeline. Controls follow SOC 2 and ISO 27001 today. Reports and questionnaires under NDA.

Last updated September 27, 2026

20xwork is an early company and we say plainly where we are.

Framework Status
SOC 2 Type II Audit period open; report expected in 2027. A bridge letter describing current controls is available under NDA.
ISO 27001 Controls aligned; certification planned after SOC 2.
GDPR DPA with Standard Contractual Clauses, EU hosting available, DPIA template on request.
HIPAA Not offered. 20xwork does not process protected health information.

We complete customer security questionnaires (SIG, CAIQ, or your own) and share our penetration test summary and policies under NDA. Email adharsh@20xwork.ai.

Have a questionnaire to fill in?

Send us your SIG, CAIQ or your own template and we will return it completed, with our penetration test summary and policies under NDA.

Email adharsh@20xwork.ai
Last updated September 27, 2026.The commitments on these pages are incorporated into our commercial agreements and Data Processing Addendum.