← Security at Apptonomy

INDEPENDENT ASSURANCE

ISO/IEC 27001 status and roadmap

ISO/IEC 27001 certifies that an organisation runs an information security management system: that it selects, operates, measures and improves its security controls. This page states where Apptonomy stands against the 2022 edition today and the path to certification.

Last reviewed:

Where we stand

We do not hold an ISO/IEC 27001 certificate, and no certification audit is underway.

Most of the security controls the standard lists are in place. The management system around them — its scope, Statement of Applicability, internal audit and management review — is what we are building now.

What exists today

  • An Information Security Policy and sixteen annexes covering organisational, people, physical and technological controls, approved on 22 September 2026.
  • A gap analysis against clauses 4 to 10 and all 93 Annex A controls of ISO/IEC 27001:2022, completed on 22 September 2026.
  • A risk management process and risk register, with every risk rated, treated by decision of the security owner, and reviewed at least annually.
  • Recurring controls with dated records, each first performed in September 2026: a control self-assessment, a quarterly access review, a backup restore test, an incident-response drill, an edge-rule review, and sanctions screening of our vendors.
  • Automated checks that report when a policy passes its review date or a recurring control has no current dated record.

Roadmap

  1. Write the management-system documents the standard requires: scope, measurable objectives, risk-acceptance criteria, and a Statement of Applicability covering all 93 Annex A controls.
  2. Operate the system, then hold an internal audit by someone who does not operate the controls, followed by a management review.
  3. Sign a declaration of conformity in the ISO/IEC 17050-1 form, available on request with the Statement of Applicability.
  4. Commission an independent penetration test of the web application and API, planned for Q1 2027.
  5. Engage an accredited certification body for the Stage 1 and Stage 2 certification audits.

Security questions

Ask for the full answers, the evidence behind them, or anything this page does not cover.

security@apptonomy.ai