Trust · Compliance
Compliance
This page holds two things a vendor risk team needs: the four ISO certificates with their scope, and our position on each regulation that matters to you, stated in its own terms. We keep the wording precise because you will be held to it if you quote us.
The four certificates
ISO 9001, quality management.
Certified.
Issuing body, certificate number, full scope statement, and expiry are withheld until verified from the signed certificate.
ISO 27001, information security management.
Certified.
Issuing body, certificate number, full scope statement, and expiry are withheld until verified from the signed certificate.
ISO 27701, privacy information management.
Certified.
Issuing body, certificate number, full scope statement, and expiry are withheld until verified from the signed certificate.
ISO 22301, business continuity management.
Certified.
Issuing body, certificate number, full scope statement, and expiry are withheld until verified from the signed certificate.
Professional memberships


Why scope matters
A certificate is only as good as its scope statement. A certificate that covers only a head office says nothing about the product you are buying. That is why each certificate must carry its scope in full, and why the security pack contains the certificates themselves, so your team can verify rather than trust.
Our posture, per regulation
Each regulation gets its own wording, because they ask different things. We never blend them into one claim.
DORA. Compliant by design, with an ongoing program.
Operational resilience, traceability, and ICT risk controls are built into the platform rather than added afterward. Readiness is a program, not a checkbox: we maintain a compliance workbook and continue to close items as banking customers and their auditors specify requirements.
The Statement of Applicability
The Statement of Applicability names the ISO 27001 controls that were excluded and why. We share it inside the security pack rather than on an open page: published openly, a list of excluded controls tells any reader exactly what we do not do. Your reviewer gets it in full. The open internet does not.
Get the security packEvidence for your review
Get the security pack
For security reviewers and vendor risk teams. The pack contains the four ISO certificates with their full scope statements, the architecture diagrams, and the data processing agreement. The Statement of Applicability is included in the pack; it is not published on the site.