Trust Centre
How MaxIron protects customer Maximo estates
The operational control position for security and procurement review: what MaxIron manages, what remains with the customer and cloud provider, where data may be processed, and which evidence your reviewer can obtain.
Page revised: 21 August 2026. Source-register links remain authoritative.
Security posture
The commitments used to operate the managed layer
Identity and endpoint protection
- Authentication
- Multi-factor authentication for human access to cloud consoles, Microsoft 365, VPN and approved SaaS services.
- Privileged access
- Named individual accounts, least privilege, no shared credentials and a semi-annual access review.
- Customer access
- VPN access with IP allow-listing. Privileged access is restricted to a small number of named people.
- Managed endpoints
- Microsoft Intune, full-disk encryption, endpoint detection and response, patch compliance and remote wipe.
Detection, response and resilience
- Cloud detection
- AWS GuardDuty, Microsoft Defender for Cloud or OCI Cloud Guard on active customer environments.
- Audit retention
- CloudTrail, Azure Activity Log or OCI Audit records retained for 12 months.
- Incident response
- P1 critical incident acknowledgement target of one hour and a four-hour resolution target, with customer notification without undue delay.
- Recovery evidence
- Production backup restores tested at least semi-annually. Engagement recovery objectives are agreed in the contract.
These are MaxIron-wide control commitments. Customer-specific architecture, recovery objectives and contractual service levels are fixed for each engagement.
Shared responsibility
Security depends on three control owners
The contracted service schedule refines this split. Unless it says otherwise, MaxIron manages the customer layer named below, the customer owns business decisions and the cloud provider secures the underlying platform.
- R1
Cloud foundation
- MaxIron controls
- Configure customer-layer identity, network controls, encryption, monitoring, audit logging, backups and security alerts on the contracted cloud platform.
- Customer controls
- Approve the cloud provider, processing region, connectivity model and any architecture constraints.
- Cloud-provider controls
- Secure the physical facilities and underlying managed infrastructure covered by the provider service.
- R2
IBM Maximo application
- MaxIron controls
- Configure HTTPS, role-based access, audit settings and supported fixes for the services named in scope.
- Customer controls
- Own business-role approval, data ownership, segregation requirements and acceptance of application changes unless the contract assigns them differently.
- Cloud-provider controls
- Operate the underlying cloud services and platform availability commitments used by the application.
- R3
Operations and recovery
- MaxIron controls
- Monitor the managed layer, respond to alerts, execute contracted backups and restore tests, and coordinate technical incident response.
- Customer controls
- Maintain business continuity outside the managed layer, name decision-makers and define service criticality, recovery priorities and escalation contacts.
- Cloud-provider controls
- Operate cloud availability, regional resilience and provider incident processes under its service commitments.
- R4
Data and suppliers
- MaxIron controls
- Process data only for the agreed service, apply the documented classification model, assess material suppliers and notify DPA customers of material sub-processor changes.
- Customer controls
- Confirm data categories, lawful basis, retention constraints and residency requirements.
- Cloud-provider controls
- Process infrastructure data under the selected cloud service terms, DPA and sub-processor arrangements.
References R1 to R4 can be cited in supplier questionnaires. Any responsibility that matters to acceptance or recovery should also appear in the contract.
Control domains
What is controlled, and what evidence supports it
The summary stays short enough to review. Open a domain for the operational commitment and the evidence available to an authorised reviewer.
Identity and privileged access
Named human accounts, multi-factor authentication and least privilege apply across cloud, VPN, Microsoft 365 and approved SaaS services. Programmatic identities use scoped keys rather than interactive sign-in. Access rights are reviewed semi-annually and revoked within five business days of a personnel or contract change.
Evidence: access-control policy, review record and joiner, mover and leaver procedure under NDA.
Cloud, network and logging
Customer environments use the cloud provider agreed for the engagement. Provider-native threat detection is enabled, customer access uses VPN and IP allow-listing, and cloud audit records are retained for 12 months.
Evidence: architecture and configuration extracts are agreed for the contracted environment.
Endpoint and personnel security
Workforce endpoints are enrolled in Microsoft Intune with full-disk encryption, endpoint detection and response, patch compliance, screen lock and remote wipe. Personnel complete screening, NDA, policy acknowledgement and annual security training before relevant access.
Evidence: device-compliance reporting and training records under NDA.
Vulnerability and change management
Supported IBM Maximo fixes and cloud changes move through documented review and change control. Vulnerabilities are assessed through the ISMS and scheduled according to risk and the support position of the affected component.
Evidence: vulnerability-management and change-control procedures under NDA, with engagement reporting defined in the service schedule.
Incident response and continuity
Incidents are classified P1 to P4. P1 acknowledgement targets one hour, with a four-hour resolution target. Material incidents affecting a customer environment trigger notification without undue delay, evidence preservation, investigation and corrective action. Production restore tests run at least semi-annually.
Evidence: incident-response and continuity procedures, plus engagement-specific recovery records under NDA.
Supplier and information governance
Suppliers are risk-classified and material providers are reviewed annually. Information is classified Public, Internal, Confidential or Restricted. Customer information is Confidential by default unless the customer specifies otherwise.
Evidence: supplier register, information-classification policy and DPA sub-processor schedule under NDA.
Data locations and sub-processors
Where data may be processed
Only the cloud platform selected for the engagement hosts that customer Maximo environment. Business services process limited operational data for the purposes stated below. Hosting regions are defaults; alternative regions can be agreed and recorded in the contract.
Customer hosting, selected per engagement
Amazon Web Services
Customer Maximo environments and selected MaxIron services
Default: Ireland (eu-west-1) or London (eu-west-2)
Microsoft Azure
Customer Maximo environments where Azure is selected
Default: UK South or North Europe
Oracle Cloud Infrastructure
Customer Maximo environments where OCI is selected
Default: UK South or Frankfurt
Business operations
- Microsoft 365
- Email, collaboration and identity
- European Union
- Microsoft Intune
- Endpoint management and device compliance
- European Union
- Cloudflare
- Website and portal edge security and DDoS protection
- Global edge
- Resend
- Transactional messages from website forms
- United States; sending region selectable
- Plausible Analytics
- Cookie-less website analytics without personal profiles
- Germany
- Cal.com
- Meeting-booking workflow
- United States or EU, by account configuration
Sub-processor approval, change notification and objection rights are governed by the DPA that applies to the engagement.
Evidence access
What your reviewer can obtain
Public assurance
- Certification
- ISO/IEC 27001:2022, issued by ISOQAR, UKAS-accredited Certification Body 0026. Verify certificate 27274. Cyber Essentials, whole-organisation scope, under the NCSC scheme. View the digital certificate.
- Control position
- The operational commitments, shared-responsibility model and sub-processor list on this page.
- Disclosure route
- security@maxiron.com for assurance questions and coordinated vulnerability disclosure.
Under NDA
- Statement of Applicability
- The current ISO 27001 Statement of Applicability, addressing all 93 Annex A controls.
- Control evidence
- Selected policies, procedures and records proportionate to the services and risk under review.
Contract-specific
- Architecture
- Cloud provider, region, network boundaries, integrations and control ownership for the customer estate.
- Recovery
- Recovery objectives, backup retention, restore frequency, maintenance windows and support coverage.
- Data protection
- Data categories, residency, retention, DPA terms, sub-processor notice and exit requirements.
Evidence is shared in proportion to the engagement and the risk under review. Restricted ISMS material is supplied to a named reviewer under NDA.
For formal due diligence
Security assurance pack
Current evidence for a named reviewer
- Current ISO certificate and certified scope statement
- Statement of Applicability and relevant control evidence under NDA
- Current sub-processor position and applicable data-processing terms
- Written answers against your questionnaire, with contract-specific gaps identified
State the services, environments and data categories under review, whether an NDA is in place, and the decision date.
Put the open security question to the control owner.
security@maxiron.com handles assurance questions and coordinated vulnerability disclosure. Include the affected service, the evidence available and a safe contact route.
Useful to include
- The questionnaire or control framework being assessed
- The Maximo environments, integrations and data categories in scope
- Your NDA status and any evidence-handling restrictions
- The approval or response date your reviewer is working to