← Security at Apptonomy
INDEPENDENT ASSURANCE
ISO/IEC 27001 status and roadmap
ISO/IEC 27001 certifies that an organisation runs an information security management system: that it selects, operates, measures and improves its security controls. This page states where Apptonomy stands against the 2022 edition today and the path to certification.
Last reviewed:
Where we stand
We do not hold an ISO/IEC 27001 certificate, and no certification audit is underway.
Most of the security controls the standard lists are in place. The management system around them — its scope, Statement of Applicability, internal audit and management review — is what we are building now.
What exists today
- An Information Security Policy and sixteen annexes covering organisational, people, physical and technological controls, approved on 22 September 2026.
- A gap analysis against clauses 4 to 10 and all 93 Annex A controls of ISO/IEC 27001:2022, completed on 22 September 2026.
- A risk management process and risk register, with every risk rated, treated by decision of the security owner, and reviewed at least annually.
- Recurring controls with dated records, each first performed in September 2026: a control self-assessment, a quarterly access review, a backup restore test, an incident-response drill, an edge-rule review, and sanctions screening of our vendors.
- Automated checks that report when a policy passes its review date or a recurring control has no current dated record.
Roadmap
- Write the management-system documents the standard requires: scope, measurable objectives, risk-acceptance criteria, and a Statement of Applicability covering all 93 Annex A controls.
- Operate the system, then hold an internal audit by someone who does not operate the controls, followed by a management review.
- Sign a declaration of conformity in the ISO/IEC 17050-1 form, available on request with the Statement of Applicability.
- Commission an independent penetration test of the web application and API, planned for Q1 2027.
- Engage an accredited certification body for the Stage 1 and Stage 2 certification audits.
Security questions
Ask for the full answers, the evidence behind them, or anything this page does not cover.
security@apptonomy.ai