Security & Compliance
Coming Soon.
Security, data protection, and compliance are core to the design and operation of PDX.
The platform and organisation have been built to meet bureau-grade expectations and to operate confidently within regulated data environments.
Data Protection & GDPR
PDX operates as a GDPR-compliant data processor.
Key principles include:
- Lawful, transparent data processing
- Purpose limitation aligned to data exchange only
- Data minimisation and controlled retention
- Clear processes for data access and correction
Data protection is embedded into platform design and operational processes.
Information Security
PDX operates in alignment with
ISO 27001 standards.
- Secure cloud-based infrastructure
- Encryption of data in transit and at rest
- Role-based access controls
- Continuous monitoring and audit logging
Security controls are applied consistently across the platform and supporting operations.
Operational Assurance
PDX has been designed to provide:
- Full auditability of data flows
- Clear traceability from submission to distribution
- Controlled access for authorised users only
These measures ensure confidence for lenders and CRAs relying on the exchange as art of their operational and compliance frameworks.