Two columns, and one of them is empty. An empty column with a date next to it is
credible. A filled one without an audit report makes everything else on this page worthless.
We meet
Nothing yet. auth00 holds no ISO 27001, no SOC 2 and no FedRAMP authorisation
today. Not "in progress" as a figure of speech — simply not held.
ISO 27001 is the one we intend to pursue first, because it is the one most procurement
processes actually ask for. No date is published here, because a date without a booked
audit is a wish.
We help meet
Where we do add weight is in your evidence: ISO 9001, 14001, 27001 and 42001 all
require records that are complete, attributable and unaltered since.
That is exactly what a seal produces. A sealed document has a fixed content, a fixed
point in time and a named sender — the three properties an auditor asks about and the
three a shared folder cannot give.
GDPR
We process in Europe and name every processor. The data subject rights — access,
portability, erasure, restriction, objection and the rules on transfers — are handled in
our privacy policy, the
data processing addendum and the
sub-processor list.
An ISO 27001 certificate would map onto much of this. We do not have one, so the
documents have to carry it on their own.
If a certificate is a hard requirement in your procurement, buy the large
vendor. We would rather say that on this page than in month three of an integration.