Compliance

Compliance
Hub

Texavio's certifications, security practices, and the compliance support we provide to clients building regulated financial products.

Active Certifications
๐Ÿ…ISO 9001Quality Management
โœ“
๐Ÿ”’ISO/IEC 27001Info Security ISMS
๐Ÿ“‹ISO/IEC 20000IT Service Mgmt
๐Ÿ“ˆCMMI Level 3Process Maturity
๐Ÿ‡ช๐Ÿ‡บGDPRData Protection
๐Ÿ›ก๏ธPen-Tested3rd-Party CREST
All certifications current ยท Last audit: Q1 2026

Last updated: June 2026

1. Our Compliance Approach

As a B2B SaaS provider of wallet infrastructure, Texavio maintains a set of infrastructure-level certifications that cover our software development processes, information security controls, and data handling practices.

Texavio is a technology company โ€” not a financial institution. Our clients are responsible for obtaining and maintaining any financial services licences, AML/KYC programmes, and regulatory approvals required for the financial products they build on top of Texavio's infrastructure. We support that process through documentation, audit tooling, and attestation letters.

2. Infrastructure Certifications

ISO 9001Certified

Quality Management Systems โ€” ensuring consistent, high-quality software development processes and service delivery.

ISO/IEC 27001Certified

Information Security Management โ€” comprehensive controls over data security, access management, and risk treatment.

CMMI Level 3Certified

Capability Maturity Model Integration โ€” defined, documented, and measured engineering and delivery processes.

ISO/IEC 20000Certified

IT Service Management โ€” structured service lifecycle governance and continual improvement.

3. Security Practices

  • MPC/TSS threshold key management โ€” no single party holds a complete private key
  • HSM-backed infrastructure for cryptographic operations
  • Regular third-party penetration testing by accredited security firms
  • GDPR-compliant data handling with documented data processing agreements
  • End-to-end encryption in transit (TLS 1.3) and at rest (AES-256)
  • Role-based access control with least-privilege enforcement
  • Immutable audit logs for all privileged operations

4. Client Compliance Support

API Audit Logs

Exportable, tamper-evident API activity logs to support your AML reporting obligations.

Compliance Documentation

Certification copies, security summaries, and data processing agreements available on request.

Sandbox for Regulator Demos

Isolated sandbox environments for demonstrating your product to regulators or auditors.

Attestation Letters

Signed letters from our compliance team for your due diligence questionnaires and vendor assessments.

5. Request Documentation

Need attestation letters or compliance documentation for your due diligence? Our compliance team will respond within 2 business days.

Contact Compliance Team

compliance@texavio.com