ISO 27001. A management system we have not built, and an excuse that does not apply here
No Solidus product has a documented information security management system. No certification body has been engaged.
What it certifies, which is not what most people assume
ISO/IEC 27001 certifies an Information Security Management System, a process, assessed by an accredited certification body. It says an organisation identified its risks, selected controls against them, documented that reasoning, operates it, and reviews it on a cycle.
It is not a statement that a product is secure. It is a statement that a company runs a disciplined process for deciding what secure means to it.
Two structural features decide what a given certificate is actually worth, and both are usually skipped:
- The scope statement. Certification applies to a defined scope, which can be one product line, one office, or one team. A certificate that excludes the system you are buying tells you nothing about the system you are buying, and the scope is in the certificate, not in the logo on the website.
- The Statement of Applicability. An organisation may exclude controls from Annex A, with documented justification. So "ISO 27001 certified" is entirely compatible with a specific control you care about having been deliberately left out. Ask which ones, and why.
We are telling you how to read a competitor's certificate here rather than hoping you do not.
Where we are, and why the previous page's reason does not transfer
Nothing exists. No ISMS, no risk register, no scope statement, no Statement of Applicability, no certification body engaged, no certificate.
On SOC 2 we gave a real reason for not having started: a Type II attests to controls operating over a period, for a company with production operations and customers, and we have neither.
That reason does not apply here, and we are not going to reuse it. ISO 27001 certifies a management system. You can build and certify an ISMS before you have a single customer, plenty of pre-revenue companies do, precisely because it is a prerequisite for the enterprise buyers they are chasing.
So the honest answer for ISO 27001 is narrower: we have not done the work. It has not been prioritised against building the product, and the internal horizon is 2027. That is a choice with a cost, and the cost is that an enterprise procurement process will stop at this page.
What this means for you concretely
- If your process requires an ISO 27001 certificate, we fail that requirement today. Not partially: there is nothing to assess.
- A "designed to ISO 27001 principles" claim is not a certificate, and you should treat it as marketing wherever you see it, including from us. We are not making that claim.
- The absence is not evidence of insecurity, and its presence would not be evidence of security. Both directions of that inference are wrong, and the only honest position is that nobody independent has looked at our security at all, which is a stronger statement than the missing certificate.
Keep reading
- Law No. 6222, identity at the turnstile, and the accreditation we do not hold
- The right to erasure versus the audit trail. The law resolves it; we have not built the workflow
- SOC 2, not engaged, not started, and not the thing most buyers think it is
- NIST iBeta". The name is wrong, the testing is real, and we have not been through it