Trust Centre

How MaxIron protects customer Maximo estates

The operational control position for security and procurement review: what MaxIron manages, what remains with the customer and cloud provider, where data may be processed, and which evidence your reviewer can obtain.

Page revised: 21 August 2026. Source-register links remain authoritative.

Security posture

The commitments used to operate the managed layer

Identity and endpoint protection

Authentication
Multi-factor authentication for human access to cloud consoles, Microsoft 365, VPN and approved SaaS services.
Privileged access
Named individual accounts, least privilege, no shared credentials and a semi-annual access review.
Customer access
VPN access with IP allow-listing. Privileged access is restricted to a small number of named people.
Managed endpoints
Microsoft Intune, full-disk encryption, endpoint detection and response, patch compliance and remote wipe.

Detection, response and resilience

Cloud detection
AWS GuardDuty, Microsoft Defender for Cloud or OCI Cloud Guard on active customer environments.
Audit retention
CloudTrail, Azure Activity Log or OCI Audit records retained for 12 months.
Incident response
P1 critical incident acknowledgement target of one hour and a four-hour resolution target, with customer notification without undue delay.
Recovery evidence
Production backup restores tested at least semi-annually. Engagement recovery objectives are agreed in the contract.

These are MaxIron-wide control commitments. Customer-specific architecture, recovery objectives and contractual service levels are fixed for each engagement.

Shared responsibility

Security depends on three control owners

The contracted service schedule refines this split. Unless it says otherwise, MaxIron manages the customer layer named below, the customer owns business decisions and the cloud provider secures the underlying platform.

  1. R1

    Cloud foundation

    MaxIron controls
    Configure customer-layer identity, network controls, encryption, monitoring, audit logging, backups and security alerts on the contracted cloud platform.
    Customer controls
    Approve the cloud provider, processing region, connectivity model and any architecture constraints.
    Cloud-provider controls
    Secure the physical facilities and underlying managed infrastructure covered by the provider service.
  2. R2

    IBM Maximo application

    MaxIron controls
    Configure HTTPS, role-based access, audit settings and supported fixes for the services named in scope.
    Customer controls
    Own business-role approval, data ownership, segregation requirements and acceptance of application changes unless the contract assigns them differently.
    Cloud-provider controls
    Operate the underlying cloud services and platform availability commitments used by the application.
  3. R3

    Operations and recovery

    MaxIron controls
    Monitor the managed layer, respond to alerts, execute contracted backups and restore tests, and coordinate technical incident response.
    Customer controls
    Maintain business continuity outside the managed layer, name decision-makers and define service criticality, recovery priorities and escalation contacts.
    Cloud-provider controls
    Operate cloud availability, regional resilience and provider incident processes under its service commitments.
  4. R4

    Data and suppliers

    MaxIron controls
    Process data only for the agreed service, apply the documented classification model, assess material suppliers and notify DPA customers of material sub-processor changes.
    Customer controls
    Confirm data categories, lawful basis, retention constraints and residency requirements.
    Cloud-provider controls
    Process infrastructure data under the selected cloud service terms, DPA and sub-processor arrangements.

References R1 to R4 can be cited in supplier questionnaires. Any responsibility that matters to acceptance or recovery should also appear in the contract.

Control domains

What is controlled, and what evidence supports it

The summary stays short enough to review. Open a domain for the operational commitment and the evidence available to an authorised reviewer.

Identity and privileged access

Named human accounts, multi-factor authentication and least privilege apply across cloud, VPN, Microsoft 365 and approved SaaS services. Programmatic identities use scoped keys rather than interactive sign-in. Access rights are reviewed semi-annually and revoked within five business days of a personnel or contract change.

Evidence: access-control policy, review record and joiner, mover and leaver procedure under NDA.

Cloud, network and logging

Customer environments use the cloud provider agreed for the engagement. Provider-native threat detection is enabled, customer access uses VPN and IP allow-listing, and cloud audit records are retained for 12 months.

Evidence: architecture and configuration extracts are agreed for the contracted environment.

Endpoint and personnel security

Workforce endpoints are enrolled in Microsoft Intune with full-disk encryption, endpoint detection and response, patch compliance, screen lock and remote wipe. Personnel complete screening, NDA, policy acknowledgement and annual security training before relevant access.

Evidence: device-compliance reporting and training records under NDA.

Vulnerability and change management

Supported IBM Maximo fixes and cloud changes move through documented review and change control. Vulnerabilities are assessed through the ISMS and scheduled according to risk and the support position of the affected component.

Evidence: vulnerability-management and change-control procedures under NDA, with engagement reporting defined in the service schedule.

Incident response and continuity

Incidents are classified P1 to P4. P1 acknowledgement targets one hour, with a four-hour resolution target. Material incidents affecting a customer environment trigger notification without undue delay, evidence preservation, investigation and corrective action. Production restore tests run at least semi-annually.

Evidence: incident-response and continuity procedures, plus engagement-specific recovery records under NDA.

Supplier and information governance

Suppliers are risk-classified and material providers are reviewed annually. Information is classified Public, Internal, Confidential or Restricted. Customer information is Confidential by default unless the customer specifies otherwise.

Evidence: supplier register, information-classification policy and DPA sub-processor schedule under NDA.

Data locations and sub-processors

Where data may be processed

Only the cloud platform selected for the engagement hosts that customer Maximo environment. Business services process limited operational data for the purposes stated below. Hosting regions are defaults; alternative regions can be agreed and recorded in the contract.

Customer hosting, selected per engagement

Amazon Web Services

Customer Maximo environments and selected MaxIron services

Default: Ireland (eu-west-1) or London (eu-west-2)

Microsoft Azure

Customer Maximo environments where Azure is selected

Default: UK South or North Europe

Oracle Cloud Infrastructure

Customer Maximo environments where OCI is selected

Default: UK South or Frankfurt

Business operations

Microsoft 365
Email, collaboration and identity
European Union
Microsoft Intune
Endpoint management and device compliance
European Union
Cloudflare
Website and portal edge security and DDoS protection
Global edge
Resend
Transactional messages from website forms
United States; sending region selectable
Plausible Analytics
Cookie-less website analytics without personal profiles
Germany
Cal.com
Meeting-booking workflow
United States or EU, by account configuration

Sub-processor approval, change notification and objection rights are governed by the DPA that applies to the engagement.

Evidence access

What your reviewer can obtain

Public assurance

Certification
ISO/IEC 27001:2022, issued by ISOQAR, UKAS-accredited Certification Body 0026. Verify certificate 27274. Cyber Essentials, whole-organisation scope, under the NCSC scheme. View the digital certificate.
Control position
The operational commitments, shared-responsibility model and sub-processor list on this page.
Disclosure route
security@maxiron.com for assurance questions and coordinated vulnerability disclosure.

Under NDA

Statement of Applicability
The current ISO 27001 Statement of Applicability, addressing all 93 Annex A controls.
Control evidence
Selected policies, procedures and records proportionate to the services and risk under review.

Contract-specific

Architecture
Cloud provider, region, network boundaries, integrations and control ownership for the customer estate.
Recovery
Recovery objectives, backup retention, restore frequency, maintenance windows and support coverage.
Data protection
Data categories, residency, retention, DPA terms, sub-processor notice and exit requirements.

Evidence is shared in proportion to the engagement and the risk under review. Restricted ISMS material is supplied to a named reviewer under NDA.

For formal due diligence

Security assurance pack

Current evidence for a named reviewer

  • Current ISO certificate and certified scope statement
  • Statement of Applicability and relevant control evidence under NDA
  • Current sub-processor position and applicable data-processing terms
  • Written answers against your questionnaire, with contract-specific gaps identified

State the services, environments and data categories under review, whether an NDA is in place, and the decision date.

Put the open security question to the control owner.

security@maxiron.com handles assurance questions and coordinated vulnerability disclosure. Include the affected service, the evidence available and a safe contact route.

Useful to include

  • The questionnaire or control framework being assessed
  • The Maximo environments, integrations and data categories in scope
  • Your NDA status and any evidence-handling restrictions
  • The approval or response date your reviewer is working to