Security, put in writing

When you entrust us with a cloud-native project or the managed hosting of your platforms, information security is not a promise: it is a management system certified ISO/IEC 27001, 27017 and 27018, verified by an independent accredited body.

Talk to our team
What changes for you

Choosing a certified partner means less risk

Why it matters. A certified information security management system does not protect a single project: it governs how we handle information across the whole organisation, from processes to technologies. For anyone entrusting us with cloud-native, managed hosting or platform development, it is the assurance that confidentiality, integrity and availability of data are managed with method, not improvised.

  1. 3 ISO/IEC certifications: 27001, 27017, 27018
  2. 2029 Certificates valid and verifiable until 2029
  3. GDPR Compliance supporting the EU data regulation
The proof

Our ISO/IEC certifications

Certificates issued by Scandinavian Certification, accredited by Norwegian Accreditation. Scope: design and development of software solutions and management of cloud service platforms. Every certificate is downloadable and verifiable.

The certification covers the company management system, not individual products or services. For the Information Security Management System policies, see the Information Security page.

How we work

SECURITY AS A SHARED RESPONSIBILITY

In the cloud, security is a shared responsibility model: part belongs to the infrastructure provider, part to whoever designs and runs the platforms. That is where we operate. Our Information Security Management System applies a systematic approach to identify, assess and treat threats, with periodic audits and management reviews. Compliance with legal and contractual requirements, with attention to GDPR, is part of the system, not a later addition.

Risk management continuous, not one-off

FAQ

Frequently asked questions about security and certifications

  • SparkFabrik is certified against three standards, issued by Scandinavian Certification (certificate ITA-10325):

    • ISO/IEC 27001:2022, information security management system

    • ISO/IEC 27017:2015, security controls for cloud services

    • ISO/IEC 27018:2025, protection of personal data in the cloud

    The certifications are valid from 7 June 2026 to 7 June 2029, with annual surveillance audits.

  • The certified scope is the design and development of software solutions and the management of cloud service platforms. The certification therefore covers both development and managed hosting.

  • No. ISO/IEC 27018 is an international standard of controls for protecting personal data (PII) in cloud services. It complements the GDPR and supports compliance with it, but does not replace it.

  • Working with a certified partner means processes verified by a third party:

    • Documented, audited risk management

    • Defined incident management procedures

    • Business continuity and access control

    • Structured support for GDPR compliance

  • The certifications are issued by Scandinavian Certification AS, accredited by Norwegian Accreditation. The body's accreditation guarantees that the audit follows international rules, making the certification verifiable and recognised.

  • Yes. ISO/IEC 27017 specifically addresses security controls for cloud services and ISO/IEC 27018 the protection of personal data in the cloud. Together with ISO/IEC 27001 they cover the entire management of SparkFabrik's cloud platforms.

Get in touch

Follow us on social media
Listen to Continuous Delivery