ISO/IEC 27001

Information Security Management System — Stage 1 complete, certification Q4.

All topics Stage 2 audit — Q4 FY26
Overview

ISO 27001 establishes the framework for our information security management system (ISMS). We completed Stage 1 (documentation review) in March 2026 with no major non-conformities; Stage 2 (operational audit) and certification are scheduled for Q4 FY26.

ISMS scope
Covered systems
All production microservices (identity, marketplace, billing, compliance, space, inventory, operations, notification).
Information assets
Customer PII, host KYC documents, contract artifacts, payment metadata, audit logs.
Supporting processes
Change management, incident response, vendor risk, business continuity, secure development.
Annex A controls (114 of 114 mapped)
A.5 Information security policies
Approved by the board annually; published internally; non-conformance triggers re-training.
A.6 Organisation of information security
CISO appointed; roles and responsibilities documented in /trust/governance.
A.8 Asset management
Asset register with classification, owner, and disposal procedure. Reviewed quarterly.
A.9 Access control
Least-privilege RBAC; quarterly access reviews; auto-revoke on offboarding (24-hour SLA).
A.12 Operations security
Capacity monitoring, malware protection, structured logging across all services.
A.16 Incident management
Documented runbook; on-call rotation; post-mortem published within 5 business days for every Sev-1.
Artifacts & references
Public docs link directly. Confidential artifacts available under NDA — request via enterprise sales.
Need more?
Want the unredacted dossier?
We can share our Stage 1 audit report and the controls-mapping spreadsheet under NDA. Useful as an annexure to your vendor-risk questionnaire.