Choosing a certified partner means less risk
Why it matters. A certified information security management system does not protect a single project: it governs how we handle information across the whole organisation, from processes to technologies. For anyone entrusting us with cloud-native, managed hosting or platform development, it is the assurance that confidentiality, integrity and availability of data are managed with method, not improvised.
Security built into every service
The certification covers the design and development of software and the management of cloud platforms: exactly the services we deliver.
Cloud-native
The platforms we design and run follow security controls certified ISO/IEC 27017, specific to cloud services.
Managed hosting
The operational management of your platforms is covered by our information security management system, with periodic audits and continuous improvement.
Personal data
The processing of personal data (PII) in the cloud follows ISO/IEC 27018 controls, supporting GDPR compliance.
Our ISO/IEC certifications
Certificates issued by Scandinavian Certification, accredited by Norwegian Accreditation. Scope: design and development of software solutions and management of cloud service platforms. Every certificate is downloadable and verifiable.
ISO/IEC 27001:2022
Information security management system (ISMS).
Certificate no. ITA-10325-ISMS, valid until 07.06.2029
ISO/IEC 27017:2015
Security controls specific to cloud services.
Certificate no. ITA-10325, valid until 07.06.2029
ISO/IEC 27018:2025
Protection of personal data (PII) processed in cloud services.
Certificate no. ITA-10325, valid until 07.06.2029
The certification covers the company management system, not individual products or services. For the Information Security Management System policies, see the Information Security page.
SECURITY AS A SHARED RESPONSIBILITY
In the cloud, security is a shared responsibility model: part belongs to the infrastructure provider, part to whoever designs and runs the platforms. That is where we operate. Our Information Security Management System applies a systematic approach to identify, assess and treat threats, with periodic audits and management reviews. Compliance with legal and contractual requirements, with attention to GDPR, is part of the system, not a later addition.
Cloud Native Services
Design and management of cloud-native platforms with certified security controls.
Supply Chain Security
Protection of the software lifecycle, from writing code to deployment.
ISMS policies
The public policies of our Information Security Management System.
Risk management continuous, not one-off