Trust, Security & Compliance.
INSIDX SECURITY & COMPLIANCE STATEMENT
Security, reliability, and transparency are core principles guiding how INSIDX For Data Exchange LLC (“INSIDX”, “IDX”, or “Company”) designs, operates, and delivers its infrastructure, hosting, cloud, and managed services.
This page describes INSIDX’s general security posture, operational practices, infrastructure model, and compliance alignment for informational and transparency purposes only.
This Statement does not create any contractual obligation, warranty, certification, guarantee, representation, or legal liability, and does not modify or override the INSIDX Master Services Agreement (“MSA”), Terms of Service (“TOS”), Data Processing Agreement (“DPA”), Service Level Agreement (“SLA”), or any other agreement governing the Services. Such agreements shall exclusively govern the rights and obligations of INSIDX and its customers.
1. INFORMATION SECURITY
INSIDX implements commercially reasonable security measures appropriate to the nature, scope, and configuration of the Services provided.
Access Control
Access to systems and administrative resources is restricted to authorized personnel based on role-based access control (RBAC), least-privilege principles, and operational necessity where applicable.
Authentication
Authentication mechanisms may be utilized, including password security policies and multi-factor authentication where supported by the applicable platform, service, or operational scope.
Data Encryption
Encryption technologies such as TLS/SSL may be utilized to protect data in transit. Encryption of data at rest may be implemented where technically feasible, commercially reasonable, and appropriate for the applicable service configuration.
Monitoring & Logging
Systems may be monitored and logged, where applicable, for operational performance, service reliability, security events, abuse prevention, and unauthorized access attempts, subject to technical feasibility and service scope.
2. SYSTEMS & INFRASTRUCTURE
Physical & Environmental Security
INSIDX services are delivered through infrastructure operated by INSIDX and/or third-party providers utilizing professionally managed data center facilities with controlled physical access, environmental safeguards, and operational security measures.
Resiliency & Backups
Where explicitly included as part of a purchased managed service, backup service, or disaster recovery offering, resiliency measures, backup mechanisms, and recovery procedures may be implemented on a commercially reasonable, best-effort basis.
Unless expressly stated in writing, unmanaged services do not include backups, disaster recovery services, data retention guarantees, or restoration commitments.
Sub-Processors & Vendors
INSIDX may engage third-party service providers, vendors, contractors, data centers, cloud providers, and sub-processors in connection with the delivery of Services.
Such providers are generally expected to maintain security measures reasonably aligned with industry standards. However, INSIDX does not control and does not guarantee the internal security practices, operational controls, service availability, or compliance status of any third-party provider.
3. COMPLIANCE & DATA PROTECTION
GDPR Alignment
Where applicable, INSIDX may process personal data as a Data Processor acting on behalf of a Customer serving as Data Controller, subject to any applicable Data Processing Agreement and GDPR-aligned privacy principles.
Legal & Regulatory Compliance
INSIDX endeavors to comply with applicable laws and regulations relevant to its operations, subject to the nature of the Services provided, contractual scope, jurisdictional requirements, and applicable legal limitations.
Data Retention
Customer data may be retained only for as long as reasonably necessary to provide the Services, fulfill contractual obligations, enforce legal rights, comply with legal requirements, or maintain legitimate operational records.
4. INCIDENT MANAGEMENT
Detection & Response
Security events may be logged, reviewed, investigated, analyzed, and addressed in accordance with internal operational procedures and applicable service scope.
Notification
Where required by applicable law, contractual obligation, or regulatory requirement, INSIDX may notify affected customers of confirmed security incidents involving personal data or material service impact.
Continuous Improvement
INSIDX periodically reviews, evaluates, and enhances its security practices as part of ongoing operational risk management and service improvement efforts.
Security Incident Disclaimer
INSIDX does not warrant or guarantee that all security incidents, vulnerabilities, threats, malicious activities, unauthorized access attempts, security risks, or emerging attack techniques will be detected, prevented, mitigated, contained, or remediated. Security controls remain subject to technological limitations, evolving threat landscapes, customer actions, service configurations, and third-party dependencies.
5. SECURITY & COMPLIANCE LIMITATIONS
INSIDX implements commercially reasonable, best-effort security controls; however, INSIDX does not and cannot guarantee absolute security, uninterrupted service availability, prevention of all cyber threats, or complete protection against data loss.
INSIDX shall not be responsible for security incidents, service interruptions, data loss, compliance failures, or other adverse outcomes resulting from:
• Customer actions, omissions, negligence, or misconfigurations
• Application-level vulnerabilities or software defects
• Customer-managed environments or unmanaged services
• Customer failure to implement appropriate security controls
• Compromised credentials or unauthorized customer access
• Third-party provider failures beyond INSIDX’s reasonable control
• Force majeure events or circumstances outside INSIDX’s reasonable control
AS IS / AS AVAILABLE BASIS
Except as expressly stated in a written agreement executed by INSIDX, all Services, infrastructure, security controls, compliance-related measures, monitoring capabilities, backup mechanisms, and operational safeguards are provided on an “AS IS” and “AS AVAILABLE” basis without warranties of any kind, whether express or implied.
OUR INFRASTRUCTURE MODEL
INSIDX operates a hybrid infrastructure model that may include:
• INSIDX-managed servers and platforms
• Private cloud environments
• Public cloud infrastructure
• Infrastructure hosted within third-party data centers
This model enables flexible and scalable service delivery while applying operational and security oversight appropriate to each service category.
SECURITY & COMPLIANCE ALIGNMENT
INSIDX’s internal practices, procedures, and service designs are intended to align with recognized international security and privacy frameworks, including:
ISO/IEC 27001 – Information Security
INSIDX security practices are designed with consideration for principles commonly associated with ISO/IEC 27001, including:
• Risk assessment and continuous improvement
• Access control and change management
• Asset management and configuration control
• Security governance and operational oversight
GDPR – Data Protection & Privacy
INSIDX endeavors to apply GDPR-aligned privacy principles where applicable, including:
• Lawful and transparent processing
• Data minimization and purpose limitation
• Appropriate technical and organizational safeguards
• Confidentiality, integrity, and availability considerations
PCI DSS – Secure Infrastructure Support
INSIDX infrastructure may support customer environments designed to pursue PCI DSS compliance objectives through controls such as:
• Network segmentation and firewalling
• Secure system configurations
• Monitoring and access logging
• Security-focused infrastructure practices
INSIDX does not claim formal certification, accreditation, audit attestation, regulatory approval, verified compliance, or official authorization under ISO, PCI DSS, SOC, GDPR, or any other framework unless expressly stated in writing.
SHARED RESPONSIBILITY MODEL
Security and compliance operate under a shared responsibility model.
INSIDX is generally responsible for:
• Infrastructure-level security controls
• Platform-level operational safeguards where applicable
• Security measures within INSIDX’s defined scope of responsibility
Customers are solely responsible for:
• Application security
• Customer content and hosted data
• Data classification and handling
• User access management
• Regulatory compliance specific to their business
• Secure configuration of unmanaged services
• Endpoint and device security
Failure by the customer to fulfill these responsibilities may limit INSIDX’s ability to provide effective security protections and releases INSIDX from related liability to the maximum extent permitted by applicable law.
CONTINUOUS IMPROVEMENT
INSIDX continuously invests in improving its security posture, operational maturity, infrastructure resilience, and compliance readiness. Future certifications, audits, attestations, or expanded compliance initiatives may be pursued as part of INSIDX’s business roadmap but are not guaranteed.
AUDITS & SECURITY ASSESSMENTS
Nothing in this Statement grants any customer, auditor, consultant, regulator, partner, or third party the right to conduct penetration testing, vulnerability assessments, security audits, inspections, scans, reviews, or examinations of INSIDX systems, infrastructure, facilities, networks, or services unless expressly authorized in writing by INSIDX.
Any approved assessment activity shall remain subject to INSIDX policies, confidentiality obligations, operational restrictions, security requirements, and advance notice requirements.
QUESTIONS & DUE DILIGENCE
Customers may contact INSIDX regarding reasonable security questionnaires, vendor reviews, compliance inquiries, or due diligence requests. Any information provided remains subject to confidentiality, security, legal, and operational limitations.
LEGAL NOTICE
This page is provided solely for informational purposes and does not constitute a warranty, guarantee, certification, audit report, compliance attestation, legal advice, regulatory guidance, professional assurance, or any form of contractual commitment.
Nothing in this Statement shall be interpreted as creating any service level commitment, uptime guarantee, security warranty, compliance obligation, or independent contractual undertaking.
Customers and third parties should not rely upon this Statement as evidence of certification, regulatory compliance, audit completion, legal compliance, or security guarantees.
INSIDX reserves the right to modify, update, amend, replace, or discontinue this Statement at any time without prior notice. The most current version published by INSIDX shall supersede all prior versions.
All Services remain governed exclusively by the applicable INSIDX agreements, including the MSA, TOS, DPA, SLA, and any executed service order.
INSIDX For Data Exchange LLC
“This page describes INSIDX security practices, infrastructure capabilities, and operational controls for informational purposes only. It does not constitute certification, audit verification, regulatory approval, legal advice, or a formal compliance attestation by any third party.”