All payments made in the preview are in test mode. Read more

Trust Center

ISO/IEC 27001:2022 control mapping

Our Information Security Management System is documented and operating against all 93 Annex A controls. Certification audits are the remaining step. Last reviewed September 9, 2026.

Scope

What the ISMS covers

The Information Security Management System (ISMS) covers the design, development, operation and support of the GuardSource security enterprise management platform delivered by GuardResourceOne, including the supporting cloud infrastructure, corporate systems and the people who administer them.

  • In scope: the production platform, its databases and file storage, the deployment pipeline, staff endpoints and identity systems.
  • Out of scope: customer-owned devices, customer-managed integrations and any physical site controlled by a customer.
  • Cloud infrastructure is inherited from certified providers; their certificates are reviewed annually and listed in our sub-processor register.

We describe ourselves as aligned to ISO/IEC 27001:2022 and in progress toward certification. We do not claim a certificate until an accredited body issues one.

Management system

Clauses 4 to 10

The requirements an auditor tests before looking at a single technical control.

Clause 4 — Context

Interested parties, internal and external issues, and the ISMS scope are documented and reviewed annually or after any material change.

Clause 5 — Leadership

Management approves the information security policy, assigns a security owner and reviews performance at a scheduled management review.

Clause 6 — Planning

A risk register scores threats by likelihood and impact against defined acceptance criteria, with treatment plans and a Statement of Applicability covering all Annex A controls.

Clause 7 — Support

Defined roles, security awareness training at onboarding and annually, and version-controlled documented information.

Clause 8 — Operation

Risk assessment and treatment are run on a set cadence and before significant changes; change control evidences the outcome.

Clause 9 — Performance evaluation

Security metrics, internal audits against Annex A, and a formal management review with recorded decisions.

Clause 10 — Improvement

Nonconformities, incidents and audit findings are logged with root cause, corrective action and verification of effectiveness.

Annex A

Controls in place today

Grouped by the four 2022 themes. Each control is evidenced in the same programme that supports our SOC 2 readiness.

A.5 Organizational controls

Policies and roles

Approved information security policy set, defined ownership and segregation of duties.

Supplier security

Sub-processors are assessed before onboarding, bound by contract and re-reviewed annually; the register is published.

Incident management

Documented response plan with severities, owners, breach notification within 48 hours of confirmation and post-incident review.

Continuity

Encrypted daily backups, tested restores, RPO 24 hours and RTO 8 hours.

Legal and privacy

Register of statutory obligations covering GDPR, UK GDPR and CCPA, with a documented retention schedule.

A.6 People controls

Screening and terms

Background checks where lawful, confidentiality agreements and security responsibilities written into employment terms.

Awareness

Security and privacy training at onboarding and annually, with completion recorded.

Offboarding

Access revoked the day someone leaves, verified against the access review record.

A.7 Physical controls

Data centres

All production data is held with certified cloud providers operating manned, access-controlled facilities; we run no server rooms of our own.

Equipment

Staff devices are encrypted, screen-locked and centrally wipeable; clear desk and clear screen expectations apply.

A.8 Technological controls

Access control

Least-privilege role-based access, single sign-on with mandatory multi-factor authentication and quarterly access reviews.

Cryptography

TLS 1.2 or better in transit, AES-256 at rest for databases, storage and backups; secrets held in a managed secret store.

Tenant isolation

Row-level security enforced in the database so a query can only return rows belonging to the authenticated account.

Logging and monitoring

Append-only audit logs of authentication, plan changes, exports and deletions, retained two years, plus uptime and error alerting.

Secure development

Peer review, automated type and lint checks, separated environments and dependency vulnerability scanning on every build.

Vulnerability management

Dependency and configuration findings are triaged on a defined SLA; an independent penetration test is scheduled before general availability.

Evidence

Requesting documentation

Security questionnaires, the Statement of Applicability summary and our risk treatment approach can be requested at security@guardresourceone.com. Certification reports are shared under NDA once issued.

See also our Security & Trust page, Sub-Processor Register and Data Processing Addendum.