ISO/IEC 27001:2022
A full 93-control Annex A Statement of Applicability is maintained and honestly dispositioned, and the ISMS went live on 26 July 2026 with its first completed management review. Not certified: no external audit has occurred, the clause 9.2 internal audit is openly unmet, and the certification trigger (a named tender, funding, or first hire) was formally decided at the first management review.
Controls mapped to this standard
Each control page lists the specific requirements it helps satisfy.
Applications · 6
Data · 8
Identity and access control · 9
- SSO-only authentication
- Row-level security tenant isolation
- Role-based access with least privilege
- Staff scope confinement
- Server-side session revocation
- Staff leaver deactivation
- No standing provider access (break-glass only)
- Privileged function gating with anonymous-surface ratchet
- Quarterly access review
Cloud infrastructure · 8
Monitoring · 11
- Daily database security sweep
- Append-only immutable audit log
- Sensitive-record read auditing
- AI-assisted change attribution
- Sending-domain authentication (SPF, DKIM, DMARC)
- Staff anomaly detection
- Uptime monitoring and public status page
- Crisis-failure alerting
- PII-scrubbed error monitoring
- External heartbeat on the security sweep
- Log access restriction
People · 3
Business operations · 10
- Governed information security policy suite
- Quarterly management review
- Measurable security objectives
- Living, procurement-shared risk register
- Nonconformity and corrective-action register
- Evidence index and CI evidence ledger
- Incident response and breach notification
- Quarterly restore drills
- Business continuity and wind-down commitments
- Annual tabletop incident exercise
Product delivery · 3
Customers · 2
Policies behind those controls
- Information security policyGovernance
- ISMS scope statementGovernance
- Security objectives and measurementGovernance
- Management review procedureGovernance
- Compliance postureGovernance
- Access control policyData security and privacy
- Data retention and lifecycle policyData security and privacy
- Data subject rights policyData security and privacy
- Crisis detection: limits and responsibilityData security and privacy
- Change management policyApplication security
- Asset inventoryInfrastructure security
- Phishing and social engineering policySecurity operations
- Logging and monitoring policySecurity operations
- Business continuity and wind-down policySecurity operations
Need the detail behind this page?
Request access and we can share the full policy set, assessment reports, and completed questionnaires under NDA — or answer your security questionnaire directly.