Trust Centre
The governed AI automation platform - secure, compliant, and responsible.
Built on AWS
SXP.ai is hosted entirely on Amazon Web Services and holds AWS Validated Partner status - independently assessed against AWS's Foundational Technical Review. Every deployment runs on the same infrastructure trusted by governments, financial institutions, and universities worldwide.
AWS Validated Partner
Independently assessed by AWS against their Foundational Technical Review - covering security architecture, operational practices, and platform resilience. Not self-certified.
Data residency by region
Customer data never leaves its region. UK and EU data is hosted in AWS London, Australian data in AWS Sydney, and US data in AWS N. Virginia - with no cross-region transfer.
NCSC Cloud Security Principles
The UK's National Cyber Security Centre (NCSC), part of GCHQ, defines 14 Cloud Security Principles used to evaluate cloud services across government and public sector. SXP.ai aligns with all 14 - providing an internationally recognised standard of cloud security assurance.
Aligned with all 14 principles
Defence-in-depth security, AES-256 encryption, and region-specific data residency - assessed against an internationally recognised framework used across UK government and public sector.
Full documentation detailing how SXP.ai meets each principle - including data protection, governance, operational security, and secure development - is available on request.
Request full documentationEU AI Act compliance
The EU AI Act is the world's first comprehensive AI regulation, setting legally binding requirements for AI systems operating in or serving the EU market. It can apply to universities outside the EU too - for example, where AI is used by students based in the EU. Rather than leave each institution to work out how every use case is classified, SXP.ai proactively applies high-risk controls across all personalised use cases, ensuring the highest standard of AI governance however the platform is used.
Built in - not bolted on
EU AI Act high-risk controls are integrated directly into our ISO 27001/27701 management system and platform - covering wellbeing, retention, student support, service automation, and any future use case.
Request full documentationFrequently asked questions
Is customer data used to train AI models?
No. Customer data is never used to train, fine-tune, or improve any AI model.
Can the AI act outside its defined scope?
No. Every capability on SXP.ai is a micro-agent locked to a single task - it can only say what it's allowed to say, access what it's allowed to access, and do what it's configured to do. SXP.ai deliberately does not deploy open-ended agentic AI. Every action is logged and auditable, with escalation to human staff where appropriate.
Where is our data stored?
Customer data stays in-region. UK and EU data is hosted in AWS London, Australian data in AWS Sydney, and US data in AWS N. Virginia.
Can we request copies of your certificates?
Yes. ISO 27001, ISO 27701 and Cyber Essentials certificates, along with NCSC Cloud Security Principles documentation and EU AI Act compliance documentation, are available on request. Request documentation
Does the EU AI Act apply to our institution?
It may. The Act can apply to institutions outside the EU where AI systems are used by, or produce outputs for, people in the EU - for example, EU-based online students. Your legal or compliance team should confirm your position. Either way, SXP.ai applies high-risk controls across all personalised use cases as standard.
Do you support WCAG 2.2 accessibility standards?
Yes. The SXP.ai platform and website are designed to meet WCAG 2.2 Level AA standards, with built-in accessibility features including high contrast mode, reduced motion, dyslexia-friendly fonts, and adjustable text sizing.
Does EU AI Act high-risk classification apply to our use case?
It depends on the use case. The Act lists specific high-risk uses in education, such as admissions, evaluating learning outcomes and monitoring students during tests. Whether other uses, such as wellbeing, retention or service automation, fall within scope depends on how they are deployed. SXP.ai doesn't leave this to chance: high-risk controls are applied across all personalised use cases as standard, so your institution is covered however your use cases are classified.
Are we locked into a single AI model or vendor?
No. The platform is model-agnostic and supports Amazon Bedrock, Claude, ChatGPT, and other providers. Different micro-agents can use different models - or a mix of models within a single micro-agent - depending on the use case. SXP.ai manages model selection and can evolve choices over time as capability, cost, and the wider AI landscape develops - without disruption to your deployment.
Which AI models does SXP.ai use?
As standard, SXP.ai runs on Amazon Bedrock using Anthropic Claude models. Where a use case requires it, the platform can also connect directly to Anthropic and OpenAI. Model selection is managed by SXP.ai and optimised per use case for capability, cost, and data residency requirements.
See how it works
A walkthrough tailored to your institution - whether you want a quick overview or a deep dive into platform architecture, governance, and deployment.
