
Certified management systems
Audited, not asserted.
Quality, environmental responsibility and information security are not claims we make about ourselves. They are management systems, certified against ISO standards and re-audited by an independent body — which means somebody outside this company checks that we do what we say.
01The standards
Three systems, independently certified
Each one is a way of working that gets audited, not a badge that gets bought. Below is what each actually governs inside a software project.
ISO 9001 — Quality management
A documented delivery process with a defined path from requirement to release: written specifications, code review before merge, tested releases, and a record of who changed what and why.
- Specification and acceptance criteria agreed in writing
- Mandatory review and automated tests before merge
- Versioned releases with a rollback path
- Defects tracked to root cause, not just to a fix
- Corrective actions recorded and reviewed
ISO 14001 — Environmental management
For a software company the footprint is infrastructure and hardware, so that is where the system applies: right-sized servers, efficient European data centres, and equipment kept in service rather than replaced on a cycle.
- Infrastructure sized to real load, not to a sales tier
- EU data centres selected on efficiency, not only on price
- Workstations and servers repaired and reused where possible
- Certified disposal for equipment at end of life
- Remote-first delivery, so travel is a choice rather than a default
ISO 27001 — Information security
The system that matters most when you hand a supplier access to your systems: how access is granted and removed, where credentials live, what happens to backups, and what we do in the first hour of an incident.
- Least-privilege access, granted per project and revoked on exit
- Credentials in a managed secret store, never in a repository
- Encrypted, off-site backups with tested restores
- Documented incident response with defined notification times
- Risk assessment before a new supplier or tool is adopted
02In practice
What certification changes, and what it does not
A certificate is evidence of a system, not a promise of an outcome. ISO 27001 does not mean nothing will ever go wrong; it means there is a defined way of granting access, a defined way of storing secrets, a defined way of responding when something does go wrong — and that an auditor has checked those definitions are followed rather than filed.
The practical difference for a client is mostly visible in the unglamorous parts of a project. Access to your systems is requested per person and removed when they leave the team. Backups are restored on a schedule rather than assumed to work. A change that touches payments or personal data goes through review by someone who did not write it. When an incident happens, there is a runbook and a notification clock, not a scramble.
It also shortens procurement. Enterprise and public-sector buyers usually have to establish these things about a supplier anyway; a certified system answers most of the questionnaire before it is asked.
03Day to day
Where you will actually notice it
Onboarding and offboarding
Access is granted per project against a named person, reviewed periodically, and removed the day someone leaves the engagement. You get a list of who holds what, on request, at any point.
Handling your data
Production data is not copied to laptops. Where a realistic dataset is needed for development, it is anonymised. Data processing agreements are signed before work starts, not after.
Change control
Nothing reaches production without review and a tested rollback. Changes to payment flows, authentication or personal data carry a heavier review than a copy change, because they should.
Incidents
A documented response: contain, preserve evidence, find the entry point, restore, then a written report with a timeline. Notification times are defined in the contract rather than negotiated during the incident.
04Procurement
The questions we are asked before a contract
Can we see the certificates?
Yes. Send a request and we will provide the current certificates, with scope and validity, along with the certification body’s registration details so you can verify them independently. We do not publish the documents on an open page, because a certificate scan on the internet is a forgery template.
Does ISO 27001 mean our data cannot be breached?
No, and any supplier who says otherwise is telling you something they cannot know. It means access, secrets, backups, supplier risk and incident response are governed by a defined system that an external auditor has tested. It substantially lowers the probability of the common failures and it defines exactly what happens if one occurs.
Is this the same as GDPR compliance?
No — GDPR is a regulation, not a certification, and no body issues a GDPR certificate that satisfies it. The two overlap heavily in practice: the access control, retention and breach-notification work required by an information security system is most of what a data protection assessment looks for. We sign a data processing agreement for every engagement and can walk you through the data flows.
What is the scope of the certification?
Software development, integration and the managed infrastructure we operate. The scope statement is printed on the certificate itself, which is the document worth reading rather than a summary of it on a web page.
Do these apply to subcontracted work?
Yes. Supplier assessment is part of the information security system, so anyone we bring into an engagement is assessed and bound by the same access and confidentiality terms. If you would rather no subcontractors touch your systems at all, that goes in the contract.
05Next step
Send the security questionnaire.
If your procurement process has one, send it over — most of it is already answered, and we will tell you plainly which parts are not. If you would rather start with the certificates themselves, ask and we will send them the same day.
