Home / About us / Trust centre
About us
Trust centre
The certifications we hold, the regulations we comply with and the controls that protect the information you trust us with.

ISO/IEC 27001
Certified

GDPR
Compliant

HIPAA
Compliant
Certifications and compliance
What has been verified
We ask our customers to prove that their security works. It is only fair that we do the same. This page sets out what has been independently verified, what we comply with and what we will share with you on request.

Certified
Information security management
ISO/IEC 27001
ISO/IEC 27001 is the international standard for an information security management system (ISMS). Our ISMS has been audited by an independent certification body, which confirms that we identify information risks and manage them through defined, working controls.
What it covers
- Risk assessment and treatment across our delivery services
- Access control, encryption and secure handling of customer data
- Incident management, logging and monitoring
- Supplier security and business continuity
- Internal audits, management review and yearly surveillance audits
What it means for you. The way we handle your systems, findings and reports is governed by an audited management system, not by individual habit.
Details
- Standard
[Edition to be confirmed] - Scope
[Certified scope] - Certification body
[Certification body] - Certificate number
[Certificate number] - Valid until
[Expiry date]

Compliant
EU data protection
GDPR
The General Data Protection Regulation (EU) 2016/679 governs how the personal data of people in the European Union is handled. When we process EU personal data on a customer’s behalf we act as a processor, and we meet the obligations the Regulation places on that role.
What it covers
- Data processing agreements that meet Article 28
- Records of processing and data protection by design
- Security of processing in line with Article 32
- Notice to the customer without undue delay if a personal data breach occurs
- Support for data subject requests and impact assessments
- Safeguards for international transfers, including Standard Contractual Clauses
What it means for you. You can engage us for work that involves EU personal data, with the contract terms and safeguards your own compliance depends on.
Details
- Our role
Processor for customer data - Assessment
[Independent assessment to be confirmed] - Sub-processors
[List available on request] - Privacy contact
info@isecurify.co - Last reviewed
[Review date]

Compliant
US health information
HIPAA
The US Health Insurance Portability and Accountability Act (HIPAA) protects health information that can identify a person. When a healthcare customer gives us access to protected health information we act as a business associate, and we apply the safeguards the HIPAA Rules require.
What it covers
- Business associate agreements with healthcare customers
- Administrative, physical and technical safeguards under the Security Rule
- Documented risk analysis and risk management
- Workforce training and role-based access to protected health information
- Audit logs, and encryption of data in transit and at rest
- Breach reporting to the customer under the Breach Notification Rule
What it means for you. Healthcare organisations and their vendors can use our testing, monitoring and advisory services without weakening their own HIPAA position.
Details
- Our role
Business associate - Assessment
[Independent assessment to be confirmed] - Agreement
Business associate agreement on request - Privacy contact
info@isecurify.co - Last reviewed
[Review date]
Draft note: ISO/IEC 27001 is a certificate issued by a certification body. GDPR and HIPAA have no single official certificate, so they are shown as compliance. Details in brackets are to be supplied.
Security practices
How we protect your information
Least-privilege access
Access to customer systems and data is granted by role, reviewed regularly and removed when an engagement ends.
Encryption
Customer data is encrypted in transit and at rest, on managed devices and managed storage.
Secure facility
Delivery work is carried out from an access-controlled office with visitor management and segregated networks.
Monitoring and response
Our own systems are monitored around the clock, with a documented incident response process.
Trained people
Staff are background-verified, sign confidentiality agreements and complete security and privacy training.
Continuity
Backups, redundant connectivity and a tested continuity plan keep our services available.
Documents
Available on request
We share the following with customers and prospective customers. Some documents are released under a non-disclosure agreement.
- ISO/IEC 27001 certificate and scope statement
- Information security policy summary
- Data processing agreement template
- Business associate agreement template
- List of sub-processors
- Summary of our latest independent penetration test

Questions
Frequently asked questions
Can we see your ISO/IEC 27001 certificate?
Yes. We share the certificate and its scope statement on request. Ask through the Talk to us page or write to info@isecurify.co.
Are you GDPR certified or HIPAA certified?
Neither law has a single official certificate. HIPAA has no certification recognised by the US Department of Health and Human Services, and GDPR certification exists only under specific approved schemes. We describe our position as compliance and share the evidence behind it on request.
Will you sign a data processing agreement or a business associate agreement?
Yes. We provide our own templates and are happy to review yours.
Where is customer data stored and processed?
[Data locations to be confirmed]
How do we report a security concern about iSecurify?
Write to info@isecurify.co with the details. Every report is acknowledged and passed to our security team.
Customer stories
What our customers say
-
Outsourcing our cybersecurity operations to iSecurify has been a strategic advantage. From real-time threat monitoring to compliance assistance, their managed services have brought us peace of mind and enabled our internal team to focus on business growth.
Swapon Adhikary
Director · The Hird
-
Following the launch of our website in both Dubai and India, we required immediate security validation to ensure platform integrity. iSecurify delivered a rapid yet comprehensive application security assessment, providing detailed and actionable findings. Their expert team collaborated directly with our developers to swiftly remediate vulnerabilities, enabling us to go live with confidence and security.
Krutarth Pandya
-
We deployed iSecurify’s iSIEM-based monitoring with automated IP blocking, and the results were immediate. Malicious IPs targeting our systems were detected and blocked in real time. The integration was seamless, and the improvement in our threat response has been significant.
Nandeep Mehta
Organisations we work with
Have a security questionnaire for us?
Send it over. We answer vendor due-diligence requests as carefully as we would want ours answered.
