



Security, Privacy & Compliance
ISO 27001 Posture
Our information security program is aligned with ISO/IEC 27001 controls, covering asset management, access control, cryptography and supplier security.
ISO 27701 Privacy
Privacy information management follows ISO/IEC 27701 practices, extending our security controls to personal data handling processes.
Data Protection
We apply GDPR and CCPA-aligned practices for data minimization, lawful processing, subject access requests and cross-border transfer safeguards.
Secure SDLC
Code review, dependency scanning and staged environments are built into our development lifecycle before any release reaches production.
Access Control
Role-based access, least-privilege provisioning and periodic access reviews govern who can reach client systems and data.
Incident Response
A documented incident response process covers detection, containment, client notification and post-incident review.
Hosting & Subprocessors
- Amazon Web Services (AWS)Primary cloud infrastructure and AWS Partner Network member
- Microsoft AzureEnterprise workloads and hybrid deployments
- Google Cloud Platform (GCP)Data and AI workloads
- DatabricksData engineering and analytics via Databricks Consulting Partner status
Shared Responsibility
NETREX operates on a shared-responsibility model with our cloud providers. Infrastructure providers secure the underlying cloud, network and physical layers, while NETREX is responsible for application-level security, configuration, access management and the secure delivery of client solutions built on top of that infrastructure.
For security disclosures or questions, reach our team directly at info@netrexinc.com or call +971 50 200 8313.