Secure by design
Your trading data stays in UK datacentres, encrypted in transit and at rest, on ISO 27001 certified infrastructure. Role-based access, customer data isolation and full audit trails, aligned to ICO and NIST guidance across the UK, EU and US.
Securing the document flows behind the retailers you know
Enterprise-grade infrastructure under every document.
Where your data lives, how it moves and how it is protected. Built to satisfy the security teams of the retailers, suppliers and logistics partners you trade with.
Your data stays where your auditors expect it.
Trading data is stored in UK datacentres certified to ISO 27001, independently audited for their information security management. Same secure platform, region-specific alignment across the UK, EU and US.
Encrypted in transit
The latest TLS secures every HTTPS connection between trading partners, integrations and XEDI.
Encrypted at rest
Data at rest is encrypted with AES-256, the standard trusted by banks and governments.
Durable cloud storage
Amazon S3 provides durable storage and queuing with automatic redundancy, so documents are never lost in flight.
Certified cloud, top to bottom.
The cloud infrastructure XEDI runs on is certified to ISO 27001, SOC 1, SOC 2 and SOC 3, and PCI DSS Level 1. Enterprise-grade foundations, without you having to take our word for it.
The fundamentals, done right.
The day-one security primitives every EDI platform should ship with, and we do.
Role-based access, enforced across the platform.
Users only see what they need. Operational teams are separated, and OAuth2 and token-based API access are supported across viewing, editing and integration.
Customer data isolation
Customer data is logically isolated, so partners and integrations only interact with the data they own.
Complete audit trails
Every document, retry and correction is logged with timestamps and event metadata.
Secure by design
Security is embedded in how XEDI is designed, operated and supported, from architecture to incident handling.
Watched around the clock.
We keep an eye on the platform so retailers, suppliers and logistics partners can trade without interruption.
Issues spotted before they reach your trading partners.
XEDI proactively monitors document flows, connection health and delivery across the platform. When something needs attention, alerting and retry workflows step in early, so orders, despatch advice and invoices keep moving.
Every secure EDI protocol you'll be asked for.
XEDI reaches the global trading grid via VAN and supports direct secure connections, including AS2 and AS4, so identity is verified on both sides of every exchange.
AS2
Direct, signed and encrypted EDI exchange, the standard for major retailers.
AS4
Modern web-services-based EDI transport with built-in reliability.
SFTP
SSH file transfer for partners that prefer a managed file-drop model.
FTPS
FTP over TLS, supported for legacy retailer connections.
API
Secure REST API over mutual-TLS HTTPS, with OAuth2 and token access.
VAN
Access to the global Value Added Network grid for retail trading partners.
Covered across the UK, EU and US.
Same secure-by-design platform, region-specific regulatory alignment. Trade where your partners are.
United Kingdom
ICO, FCA
- Aligned to the ICO Data Security Guide for personal data handling.
- UK GDPR and Data Protection Act 2018 compliant trading data flows.
- Connected to UK retailers, suppliers and 3PL networks.
European Union
EDPB
- GDPR-aligned processing for cross-border EDI between EU partners.
- Direct connections with EU retailer and grocery groups.
- Multi-language and multi-currency document workflows.
United States
NIST
- Aligned to the NIST Cybersecurity Framework for controls and practices.
- Direct connectivity to US trading partners across retail and dropship.
- Compatible with X12 EDI standards used by US retail networks.
Built for every side of the supply chain.
The same platform, tuned to how retailers, suppliers and logistics partners actually trade, and what each side needs to prove on audit day.
Retailers
Onboard suppliers safely with controlled flow access, full audit visibility on POs, ASNs and invoices, and inbound or outbound governance per trading partner.
Suppliers
Trade with every retailer from one secure account. Identity-verified connections, role-based team access, and granular event logs for every document.
Logistics
Exchange labels, tracking, ASNs and PODs with retailers and 3PL networks over signed, encrypted channels, with manual retry and correction workflows when needed.
Aligned to the standards your auditors already know.
Our security approach references the frameworks regulators and customers ask about, and our team's certifications are published for you to verify. No overclaiming what we don't hold.
Security you can check.
We know security questions come up before a new platform is approved. Here are the credentials, checks and documents we can share when your team needs them.
Cyber Essentials certification
XEDI holds Cyber Essentials certification for baseline cyber security controls. Certification evidence can be shared during supplier onboarding and security review.
Daily OWASP security reporting
XEDI maintains daily OWASP-focused application security reporting to monitor common web application risks and support continuous review.
Cyber and technology insurance
XEDI maintains business insurance covering cyber and technology risk. Insurance evidence can be provided through the procurement process where required.
OWASP reports, certification evidence and insurance documentation can be provided through the appropriate supplier review process. Public availability may vary where reports contain operational or security-sensitive detail.
Security questions, answered.
Your trading data is stored in UK datacentres, so it stays within the jurisdiction your customers and auditors expect. The infrastructure is certified to ISO 27001 and independently audited for its information security management.
Data is encrypted in transit with the latest TLS on every HTTPS connection, and encrypted at rest with AES-256, the same standard trusted by banks and governments.
XEDI holds Cyber Essentials certification for baseline cyber security controls, and our security team's CCZT and CCSK certifications are published on Credly for you to verify. Separately, the datacentres and cloud storage XEDI runs on are certified to ISO 27001, SOC 1, SOC 2 and SOC 3, and PCI DSS Level 1. We are deliberate about that distinction: those are certifications held by the infrastructure beneath the platform, not by XEDI itself.
Cyber Essentials certification evidence, daily OWASP application security reporting and cyber and technology insurance documentation can all be provided through the appropriate supplier review or procurement process. Public availability may vary where reports contain operational or security-sensitive detail.
Customer data is logically isolated inside the platform, so partners and integrations only interact with the data they own. Each trading relationship has its own controlled access.
Access is role-based, so users only see what they need. Operational teams are separated, and OAuth2 and token-based API access are supported across the platform.
AS2, AS4, SFTP, FTPS and a secure REST API over mutual-TLS HTTPS for direct connections, plus access to the global Value Added Network (VAN) grid for retail trading partners.
Yes. Every document, retry and correction is logged with timestamps and event metadata, giving finance and compliance teams full governance over what happened and when.
The UK, EU and US, with region-specific regulatory alignment: the ICO Data Security Guide and UK GDPR in the UK, GDPR across the EU, and the NIST Cybersecurity Framework in the US.