Trust at 3E
Security and trust are foundational to how we build and operate our technology. Our information security program is structured around the ISO 27001 framework and the NIST Cybersecurity Framework, guiding how we approach risk management, vulnerability management, penetration testing, and data protection. Compliance requirements including SOC 2 and GDPR are maintained and audited annually.
3E operates a responsible AI governance framework aligned with the EU AI Act and NIST AI RMF, and is pursuing ISO 42001 certification. We apply a human-over-the-loop approach, ensuring human accountability is embedded across all AI systems — from design through operation.
Compliance

SOC 2 Type 2
Service Organization Controls (SOC 2) (Type II) trust services principles for 3E Exchange and general IT service and organizational security controls common across our full product suite.
GDPR
3E is certified under the EU-US and SWISS-US Data Privacy Framework (DPF), and compliant with GDPR
TISAX
The ENX Association supports with TISAX (Trusted Information Security Assessment Exchange) on behalf of VDA the common acceptance of Information Security Assessments in the automotive industry. The TISAX Assessments are conducted by audit providers that demonstrate their qualification at regular intervals. TISAX and TISAX results are not intended for general public. For the 3E Europe GmbH confidentiality, availability and integrity of information have great value. We have taken extensive measures on protection of confidential information with Very High Protection Needs. The result for the Scope ID and Assessment ID is exclusively retrievable over the ENX portal. : https://portal.enx.com/en-US/TISAX/tisaxassessmentresults

ISO
ISO 9001 certified for 3E Protect obtainment and 3E ERD Authoring services.
Resources
3E AI Platform
Architecture and Security
3E Protect
Application Security and IT Controls
3E Exchange
Application Security and IT Controls
3E ERC+
Data Security and IT Controls
3E ERD
Application Security and IT Controls
3E Generate
Application Security and IT Controls
3E Insight for Chemicals
Application Security and IT Controls
3E Notify (3E Generate)
Application Security and IT Controls
3E Notify for Poison Centres (SAP)
Application Security and IT Controls
SOC 2 Type II Report
Monitoring
Subprocessors
AWS
Cloud Services Infrastructure
Azure
Cloud Services Infrastructure
Zendesk
Customer Support
Salesforce

Okta
Secure Identity for Employees and Customers
