Assurance Map
Everything we attest to, mapped on one page
If a procurement team can’t answer ‘what standards do you meet, by whom, until when, and where’s the proof?’ in five minutes, the vendor is wasting their time. Here’s ours.
Active attestations
7
External auditors
Frameworks mapped
12
Across security, privacy, AI, payments
Regions covered
EU · UK · US · HK
Plus customer data residency
Last refresh
2026-06-29
Refreshed at every change
Register
| Standard | Status |
|---|---|
| SOC 2 Type II | Current |
| SOC 1 Type II | Current |
| ISO/IEC 27001:2022 | Current |
| ISO/IEC 27017:2015 | Current |
| ISO/IEC 27018:2019 | Current |
| ISO/IEC 27701:2019 | In progress |
| PCI DSS v4.0 (SAQ-A) | Current |
| GDPR (EU) | Mapped |
| EU AI Act — Limited Risk | Mapped |
| DORA mapping | Mapped |
| NIST CSF 2.0 | Mapped |
| CSA CAIQ v4 | Current |
Standing commitments
- Every certificate and bridge letter is published the day it’s signed, not the quarter it’s convenient.
- Any lapse — even by a single day — triggers an entry on the trust ledger.
- Customer auditors get direct read access to the underlying evidence vault under NDA.
- We never claim a standard we don’t have. ‘Mapped’ means cross-walked, not attested.