The certification
The design, development and delivery of the Control Management platform are governed by an information security management system certified to ISO/IEC 27001:2022, integrating the ISO/IEC 27017:2015 controls specific to cloud services, certified by Bureau Veritas Italia S.p.A. and accredited by Accredia.
Organisation with an information security management system certified to ISO/IEC 27001:2022
Information security by design, not as a slogan
ISO/IEC 27001:2022
The international standard for information security management systems (ISMS): risk assessment and treatment, security controls, monitoring and continual improvement, verified by an accredited third-party body.
ISO/IEC 27017:2015 controls
The management system integrates the additional controls set out in the ISO/IEC 27017:2015 guidelines, specific to cloud services. This is not a separate certification: these controls are integrated into the ISO/IEC 27001:2022 certification.
A management system certified to ISO/IEC 27001:2022, with the ISO/IEC 27017:2015 controls for the cloud, supporting our commitment to protecting personal data.
Scope of certification
Design, development and delivery of cloud software for managing documentation in the fields of quality, occupational health and safety and environmental protection, with the additional controls set out in the ISO/IEC 27017:2015 guidelines for cloud services.
Unofficial translation of the scope: the certificate is the reference document.