ISO 27001:2022
We are building our information security management system (ISMS) to the ISO 27001:2022 standard and are working towards independent certification, covering all cloud and on-premise deployments.
Zero-trust architecture and independent penetration testing today, with ISO 27001:2022, SOC 2 Type II, and FedRAMP on our compliance roadmap and GDPR-aligned data handling.
Compliance roadmap
Our target compliance framework across security, privacy, accessibility, and government cloud standards — certifications in progress, with status available on request.
We are building our information security management system (ISMS) to the ISO 27001:2022 standard and are working towards independent certification, covering all cloud and on-premise deployments.
A SOC 2 Type II examination is on our compliance roadmap, covering the Security, Availability, and Confidentiality trust service criteria. Reports will be available under NDA for enterprise customers once complete.
FedRAMP authorisation is on our roadmap for US federal agency customers who require cloud authorisation.
Security controls are mapped to NIST Cybersecurity Framework 2.0 across all six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
Data Processing Agreements (DPAs) available for all EU-region customers. Data residency options in Frankfurt, Dublin, and Stockholm. EU SCCs in place for all sub-processors.
All Airfree web interfaces meet WCAG 2.2 Level AAA accessibility requirements. Regular audits are conducted using automated tooling and assistive technology testing.
Architecture
Six defence-in-depth controls applied uniformly across SaaS, private cloud, and air-gapped deployments.
TLS 1.3 in transit, AES-256 at rest. Customer-managed keys (CMK) supported via AWS KMS, Azure Key Vault, or HashiCorp Vault for enterprise deployments.
Every service-to-service call is mutually authenticated via mTLS. No implicit trust based on network location — identity is verified at every hop using SPIFFE/SPIRE.
Role-based access control layered with attribute-based policies. Fine-grained permissions down to individual dataset, layer, and feature level using Open Policy Agent (OPA).
Multi-factor authentication enforced for all user accounts, service accounts, and administrative interfaces. FIDO2 / WebAuthn hardware keys supported for privileged access.
Every data access, configuration change, and administrative action is written to a cryptographically chained audit log stored in write-once object storage. Tamper-evident by design.
Independent black-box and grey-box penetration testing is part of our security programme, with findings and remediation timelines shared with enterprise customers.
We share our current compliance status and roadmap with enterprise customers — including penetration-test summaries, completed security questionnaires, and SOC 2 and ISO documentation as those certifications complete.