Security & Compliance

Coming Soon.
Security, data protection, and compliance are core to the design and operation of PDX.

The platform and organisation have been built to meet bureau-grade expectations and to operate confidently within regulated data environments.

Data Protection & GDPR

PDX operates as a GDPR-compliant data processor.

Key principles include:

  • Lawful, transparent data processing
  • Purpose limitation aligned to data exchange only
  • Data minimisation and controlled retention
  • Clear processes for data access and correction

Data protection is embedded into platform design and operational processes.

Information Security

PDX operates in alignment with
ISO 27001 standards.

  • Secure cloud-based infrastructure
  • Encryption of data in transit and at rest
  • Role-based access controls
  • Continuous monitoring and audit logging

Security controls are applied consistently across the platform and supporting operations.

Operational Assurance

PDX has been designed to provide:

  • Full auditability of data flows
  • Clear traceability from submission to distribution
  • Controlled access for authorised users only

These measures ensure confidence for lenders and CRAs relying on the exchange as art of their operational and compliance frameworks.