Skip to content
Trust

Security & compliance, audited.

Infosistema is certified to ISO/IEC 27001 (information security) and ISO 9001 (quality management). Both certifications cover the design, development, operation, and support of every Infosistema product. Below — the certifications themselves, the operating principles that back them, and how to request a certificate copy for procurement.

Independent verification

Certifications

Audited annually by independent certification bodies. Certificate copies and full scope statements available on request — email privacy@infosistema.com.

ISO/IEC 27001 mark of trust

ISO/IEC 27001

Information Security Management

Body
BSI
Audited
Annually
Coverage
Design, development, operation, and support of all Infosistema products and services — including DMM Infinity, DocDigitizer, BizAPIs, BizSupply, and Arena.
Extensions
ISO/IEC 27017 (cloud-security controls), ISO/IEC 27018 (protection of personal data in cloud).
ISO 9001 mark of trust

ISO 9001

Quality Management

Body
IQNET
Audited
Annually
Coverage
Design, development, operation, and support of all Infosistema products and services. Audited end-to-end, from project intake to ongoing maintenance.
Additional frameworks
GDPR·Data protection (EU)
CCPA·Data protection (California)
OWASP·Application security
Operating principles

How the certifications hold up in practice

The certifications above describe an audit. These are the four operating principles that make the audit pass every year.

Customer data stays where it belongs

Each product is designed so customer data lives in tenant-scoped storage. We do not use Customer Data to train models or for any purpose outside service delivery.

Region-pinned infrastructure

EU customers stay in EU regions (europe-west1); US customers stay in US regions (us-central1). Region pinning is contractual, not best-effort.

Least-privilege access, time-bound

No standing admin credentials in production. Privileged access is per-environment, audited, and expires.

Incident response — documented, rehearsed

Runbooks for credential rotation, breach notification (72 hours per GDPR), and post-incident review live in the same repo as the code they protect.

Need a certificate copy or a security review?

Procurement teams and security reviewers can request ISO certificate copies, scope statements, and Infosistema’s standard Data Processing Agreement (DPA). For privacy enquiries see the Privacy Policy.