Certifications & attestations

Independently audited, on a public schedule

Every report below is held by an independent third party. We publish issue dates, expiry, scope, and a path to request the report under NDA — no “trust us” logos, no expired badges.

Active certifications

6

With named auditor

Jurisdictions covered

EU · UK · US

Plus DORA readiness

Reports renewable

Annual

Surveillance audits in between

Open findings

0 critical

2 informational, both in flight

SOC 2 Type II

Active

Trust services · auditor: Coalfire (independent)

Issued 2025-11-04

Expires 2026-11-03

Security · Availability · Confidentiality across production workloads, identity, treasury, and AI services.

Request: NDA-gated · /security/soc2

ISO/IEC 27001:2022

Active

ISMS · auditor: BSI

Issued 2025-09-22

Expires 2028-09-21

Information Security Management System covering EU and US delivery; surveillance audits annual.

Request: Public certificate · /attestations

ISO/IEC 27017:2015

Active

Cloud security · auditor: BSI

Issued 2025-09-22

Expires 2028-09-21

Cloud-specific controls for tenant isolation, shared-responsibility, and key management.

Request: Public certificate · /attestations

ISO/IEC 27018:2019

Active

Cloud privacy · auditor: BSI

Issued 2025-09-22

Expires 2028-09-21

Protection of personally identifiable information in public cloud processing.

Request: Public certificate · /attestations

PCI DSS v4.0 SAQ A-EP

Active

Payments · auditor: QSA (Foregenix)

Issued 2026-01-18

Expires 2027-01-17

Cardholder data environment scope: tokenised payments and treasury rails. No PAN storage.

Request: NDA-gated · /security/questionnaire

GDPR Art. 30 records

Active

Privacy · auditor: DPO + external counsel (Bird & Bird)

Issued 2026-02-04

Expires Continuous

Records of processing activities, ROPA, and lawful basis register; aligned with /legal/dpa.

Request: Public ROPA summary · /legal/privacy

DORA readiness assessment

In observation

EU resilience · auditor: KPMG advisory

Issued 2026-01-30

Expires Reviewed annually

ICT risk framework, incident reporting, digital operational resilience testing, third-party risk register.

Request: Summary · /regulatory-map

TISAX (planned)

Annual renewal

Automotive supply · auditor: ENX-listed assessor

Issued Kickoff 2026-04

Expires Targeted 2026-Q4

Information security for automotive customers; assessment level AL3.

Request: Roadmap · /open-roadmap

HIPAA controls mapping

Mapped

US health · auditor: Internal + legal

Issued 2025-12-12

Expires Reviewed annually

Mapping of safeguards to HIPAA Security Rule; ADmetric is not a covered entity but supports BAA on request.

Request: BAA · contact@admetric.ai

How we run audits

  • Auditor independence is signed every year on /independence; we rotate firms when independence weakens.
  • Findings — critical, high, medium, low, informational — are published count-only on /attestations within 30 days of report receipt.
  • We never delay a report to influence its findings. The report ships when the auditor signs it.
  • Customer-facing scope changes (new region, new product, new sub-processor) are reflected in the next surveillance audit, not at the annual cycle.