Company news
AYON achieves SOC 2 Type 2, ISO 27001 and GDPR compliance

Animation and VFX studios create and manage valuable work every day, from unreleased footage and client material to project information, reviews and production data. When a platform becomes part of that production environment, the way that information is protected matters just as much as what the software can do.
AYON has now achieved compliance with SOC 2 Type 2, ISO 27001 and GDPR, covering three of the major security and data protection requirements we’re regularly asked about by studios and larger organisations around the world.
For customers working with US companies, SOC 2 Type 2 is an established requirement during many vendor and security reviews. ISO 27001 is internationally recognised and widely used by organisations to assess how suppliers manage information security. GDPR covers the handling and protection of personal data for organisations operating in or working with people in the European Economic Area.
Together, they give studios and their clients clearer evidence that the systems and processes behind AYON are being operated with recognised security and data protection practices in place.
Secure by design for creative production
Security requirements in animation, VFX and other creative industries have grown considerably as productions have become more distributed and more infrastructure has moved online. Studios may be working with unreleased films, episodic content, advertising campaigns or other material that can't simply be exposed outside the people and systems authorised to see it.
AYON can sit at the centre of that production environment, connecting artists, supervisors, production teams and technical departments around project information, versions, reviews and other production context.
Achieving these compliance standards gives security, IT and procurement teams a recognised framework against which they can assess how AYON is operated. It also means we can provide the supporting information customers increasingly need when AYON is being considered for larger productions or organisations with formal vendor-security requirements.
Keeping the standards in place
We worked with Comp AI to manage the compliance process, including the controls, policies and evidence needed across the different frameworks. The work also gives us a structure for continuing to monitor and improve our security practices rather than treating compliance as a box that only needs to be ticked once.
Customers and security teams can view our current compliance status, policies and supporting security information through the Ynput Trust Centre.