Fxiaoke · Trust Center

Fxiaoke Trust Center

Trust center

Fxiaoke maintains a public trust center documenting ISO/IEC 27001, ISO/IEC 27701, ISO/IEC 20000-1, ISO 9001, MLPS / 等级保护, SOC 1, and SOC 2 compliance.

CompanyEnterpriseCRMSalesMarketingCustomer ServiceSaaSChinaPaaS
Trust center:

Certifications & Compliance

ISO/IEC 27001ISO/IEC 27701ISO/IEC 20000-1ISO 9001MLPS / 等级保护SOC 1SOC 2

Source

Trust Center

fxiaoke-trust-center.yml Raw ↑
generated: '2026-08-13'
method: searched
source: https://www.fxiaoke.com/secure/index.html
trust_center_url: null
note: >-
  Fxiaoke operates no dedicated trust center, security portal or compliance-document
  request page. The certification inventory below is published in section 4.3.2
  (安全体系认证) of the privacy policy — a legal document, not a security page — which is
  the only public surface naming them.

certifications:
- name: ISO/IEC 27001
  full: GB/T22080-2016 / ISO/IEC 27001 信息安全管理体系认证证书
  category: information-security-management
  level: null
  verified: named in the provider's own privacy policy
- name: ISO/IEC 27701
  full: ISO/IEC 27701 隐私信息管理体系认证证书
  category: privacy-information-management
  level: null
  verified: named in the provider's own privacy policy
- name: ISO/IEC 20000-1
  full: ISO/IEC 20000-1 信息技术服务管理体系认证证书
  category: it-service-management
  level: null
  verified: named in the provider's own privacy policy
- name: ISO 9001
  full: GB/T19001-2016 / ISO 9001:2015 质量管理体系认证证书
  category: quality-management
  level: null
  verified: named in the provider's own privacy policy
- name: MLPS / 等级保护
  full: 信息系统安全等级保护备案证明(三级)
  category: china-classified-protection
  level: Level 3
  verified: named in the provider's own privacy policy
  note: >-
    China's Multi-Level Protection Scheme, Level 3 — the level normally required of a
    commercial system handling significant volumes of personal information.
- name: SOC 1
  full: SOC 1 (Type II)
  category: service-organization-controls
  level: Type II
  verified: named in the provider's own privacy policy
- name: SOC 2
  full: SOC 2 (Type II)
  category: service-organization-controls
  level: Type II
  verified: named in the provider's own privacy policy

quote:
  zh: >-
    目前,我们的重要信息系统已经通过GB/T22080-2016/ISO/IEC27001(信息安全管理体系认证证书)、
    ISO/IEC27701(隐私信息管理体系认证证书)、ISO/IEC20000-1(信息技术服务管理体系认证证书)、
    GB/T19001-2016/ISO9001:2015(质量管理体系认证证书)、信息系统安全等级保护备案证明(三级)、
    SOC 1 (Type Ⅱ)及SOC 2 (Type Ⅱ) 等在内的多项个人信息保护相关国际权威认证。
  source: https://www.fxiaoke.com/secure/index.html

report_access:
  soc2_report_available: unknown
  process: >-
    No mechanism is published for requesting a SOC 2 report, an ISO certificate PDF, or
    a security questionnaire. The certifications are asserted in prose with no
    certificate numbers, issuing bodies, audit dates or validity periods, so none can be
    independently verified from the public surface.

data_residency:
  primary: China (中华人民共和国境内)
  statement: >-
    Personal information collected in the course of operations in China is stored in
    China. Cross-border access can occur where a tenant enables the interconnected-
    enterprise (互联) feature with an overseas Fxiaoke tenant.
  regional_api_hosts:
  - open.fxiaoke.com (纷享云)
  - open-hwcloud.fxiaoke.com (华为云)
  - open-ale.fxiaoke.com (阿里云)
  - open-hws.fxiaoke.com (法兰克福 / Frankfurt)
  - open-ksc.sharecrm.com (香港华为 / Hong Kong)
  - open-na.sharecrm.com (北美云 / North America)
  source: https://developer.fxiaoke.com/openapi_v2/start/guide/cloud.html

privacy_program:
  contact: privacy@fxiaoke.com
  dedicated_team: 设置了个人信息保护专职部门 — a dedicated personal-information protection department
  incident_response: >-
    The policy commits to an emergency plan, notification by SMS/phone/push, and
    reporting the incident to the regulator, but publishes no target timeline.
  entity: 北京纷扬科技有限责任公司, 北京市海淀区知春路甲63号卫星大厦7层
  hotline: '4001122778'

gaps:
- No security.txt on any host (RFC 9116) — see well-known/fxiaoke-well-known.yml
- No vulnerability disclosure policy or bug bounty program found
- No dedicated security or trust page; certifications live only inside the privacy policy
- No certificate identifiers, auditors or validity dates published
- No status page and no published SLA — see lifecycle/fxiaoke-lifecycle.yml

ref:
  domain_security: security/fxiaoke-domain-security.yml
  conformance: conformance/fxiaoke-conformance.yml