Skip to main content
Certifications and accreditations

We announce what can be verified not certificates hung without support

This page rests on one rule: we announce no certificate we do not hold. The register below stays empty when no valid certificate exists, and every entry names its issuing body, number, scope and validity dates so a reader can verify it independently. What we operate without a certificate we call a control rather than an accreditation — because calling a control a certification is the first step of fabrication.

  • A register, not a logo wall
  • Every entry has a body, number, scope and dates
  • A control is not called a certification
  • We are no certification body and certify no client
  • We invite verification, not belief

Direct answers

The questions asked first

Are you certified to ISO or an equivalent standard?

We announce no certificate we do not hold, and our register below is currently empty — not one certificate. We say that plainly rather than hang a badge: a certificate is either valid, in our name, with its number, issuing body and dates, or it is not mentioned. If we obtain one later it will be listed with its full details, and you can then verify it with the issuing body rather than with our page.

So what do you operate with?

We operate with written controls: least privilege and an access log, separated test and production environments, backups whose restore is tested, security-update management, documentation and handover, and a change log with periodic review. We call them controls, not certifications, because the difference is fundamental: a control is measured, implemented and documented, whereas a certification is granted by a third party after audit — and we should not call one the other to look better.

Do you issue certificates to our clients or manage their accreditation?

No. We are not a certification body, an audit body or a certificate issuer: we issue no certificates, manage no accreditation on your behalf and represent you before no issuing body. What we do is implement the controls and the documented procedures your auditor asks for and produce the evidence from your system, while the audit and the accreditation stay between you and the competent body. Anyone offering you a “certificate” from us is offering a document with no accreditation value.

How do we verify a certificate of yours, if one exists?

In four steps: ask for the certificate number and the issuing body; ask for its exact scope (activity, sites and duration); then check the issuing body’s register where it publishes one; and confirm the validity, expiry and renewal dates. We list those details in the register whenever a certificate exists, and we facilitate any verification a party or client requests. The principle: verifying with the issuing body is stronger than trusting a page — which is what we ask of you towards us, as we apply it to ourselves.

Register

The certifications register

Every certificate listed here carries its issuing body, number, scope and issue and expiry dates. Where none exists, nothing is written in the register — the absence is stated plainly instead.

The register is currently empty: no certificate is announced. We have listed no “in-progress” certificates and no “certified by our partners”, because a row without a body, a number and a scope is not a certificate but a badge. When we hold a valid certificate it will be listed here with its full details.

We name this emptiness as it is: a gap stated rather than hidden. We know a certifications page is usually built from badges placed to persuade, and that the absence of a badge is read by some as weakness; we still prefer an honest empty register to a wall that casts doubt on everything else we write.

Controls

Controls we operate without a certificate

Six written, measured controls. We call them controls rather than accreditations, because a wrong label empties the word of meaning.

Least privilege and an access log

Each user holds the least access their role needs, with a log showing who opened or edited and when.

What it suffers from
Each user holds the least access their role needs, with a log showing who opened or edited and when.
What fits it
Each user holds the least access their role needs, with a log showing who opened or edited and when.

What does not fit you: A control, not a certificate

Backups with a tested restore

Periodic backups and, more importantly, a recorded actual restore test — because a backup that is not restored is not a backup.

What it suffers from
Periodic backups and, more importantly, a recorded actual restore test — because a backup that is not restored is not a backup.
What fits it
Periodic backups and, more importantly, a recorded actual restore test — because a backup that is not restored is not a backup.

What does not fit you: Tested, not assumed

Test and production separation

No experimenting on production data, and no release without testing in a separate environment first.

What it suffers from
No experimenting on production data, and no release without testing in a separate environment first.
What fits it
No experimenting on production data, and no release without testing in a separate environment first.

What does not fit you: Separated environments

Security-update management

Tracking platform and dependency updates and applying them within a declared time, because delay is the practical vulnerability.

What it suffers from
Tracking platform and dependency updates and applying them within a declared time, because delay is the practical vulnerability.
What fits it
Tracking platform and dependency updates and applying them within a declared time, because delay is the practical vulnerability.

What does not fit you: Within a declared time

Documentation and orderly handover

Architecture documentation, an operations guide and credentials handed over, because an undocumented system becomes a hostage.

What it suffers from
Architecture documentation, an operations guide and credentials handed over, because an undocumented system becomes a hostage.
What fits it
Architecture documentation, an operations guide and credentials handed over, because an undocumented system becomes a hostage.

What does not fit you: Before handover

A change log and periodic review

A log of every change to the systems and a periodic review of it, because an unrecorded change becomes an unknown cause later.

What it suffers from
A log of every change to the systems and a periodic review of it, because an unrecorded change becomes an unknown cause later.
What fits it
A log of every change to the systems and a periodic review of it, because an unrecorded change becomes an unknown cause later.

What does not fit you: A trace per change

These controls are implemented and measured, and their evidence can be requested: a written policy, an execution log or a restore test report. They are less than what an audited certificate attests — a difference stated here plainly rather than hidden in a general phrase.

Verification

How to verify any announced certificate

Four steps we ask of you towards us, as we apply them to ourselves — a page that does not survive them should not be read.

Ask for the body and the number

A certificate without an issuing body and a number is not a certificate but an image.

Ask for the exact scope

Which activity, which sites, which period — because a scope wider than reality makes the certificate misleading.

Check the issuing body’s register

Verifying with the issuing body is stronger than trusting a page — and this applies to your own certificates too.

Confirm the dates

Issue, expiry and renewal dates, because an expired certificate announced as valid is worse than none.

Not announced

What we do not announce

Four promises you will not find on this page, each with the reason it is refused.

Method

    Measurement

    What we measure in the controls

    Indicators read from operations, because a control that is not measured can neither be evidenced nor improved.

    Backups and restore tests

    Backup frequency and recorded restore-test success, because a backup that is not restored does not count.

    Time to apply security updates

    From an update’s release to its application in production, because delay is the practical vulnerability.

    Access-log completeness

    The share of data opens or edits logged with who performed them and when.

    Test and production separation

    Any work on production data without a separate test environment — the target being zero.

    Documentation completeness at handover

    The share of handovers accompanied by architecture documentation, an operations guide and credentials.

    We announce no security percentage, no protection level and no accreditation, and we do not present these indicators as a certificate. What we measure is backup frequency and restore-test success, time to apply security updates, access-log completeness, separation of test from production, and documentation completeness at handover — figures about our own operations.

    Client-side

    What belongs to you rather than to us

    In many projects a client’s certificate is conflated with a vendor’s, so the separation is written out plainly.

    Your activity licences

    Commercial and regulatory licences are in your entity’s name; we hold none and represent you in no procedure for them.

    Your operating permits

    Operating permits in your field — some need a system that produces their evidence, and we produce the evidence rather than the permit.

    Certificates your clients ask of you

    Conformity or quality a client asks of you; we implement the evidence and controls for your audit while the accreditation stays yours.

    Your clients’ data declarations

    The lawful basis, declarations and data-subject consents are your responsibility as controller, and we account for that during implementation.

    Client-side

    What belongs to you rather than to us

    In many projects a client’s certificate is conflated with a vendor’s, so the separation is written out plainly.

    FAQ

    Questions about certifications

    Direct answers on certificates, controls, verification and what we do not provide.

    Are you certified to ISO or an equivalent standard?

    We announce no certificate we do not hold, and our register below is currently empty — not one certificate. We say that plainly rather than hang a badge: a certificate is either valid, in our name, with its number, issuing body and dates, or it is not mentioned. If we obtain one later it will be listed with its full details, and you can then verify it with the issuing body rather than with our page.

    So what do you operate with?

    We operate with written controls: least privilege and an access log, separated test and production environments, backups whose restore is tested, security-update management, documentation and handover, and a change log with periodic review. We call them controls, not certifications, because the difference is fundamental: a control is measured, implemented and documented, whereas a certification is granted by a third party after audit — and we should not call one the other to look better.

    Do you issue certificates to our clients or manage their accreditation?

    No. We are not a certification body, an audit body or a certificate issuer: we issue no certificates, manage no accreditation on your behalf and represent you before no issuing body. What we do is implement the controls and the documented procedures your auditor asks for and produce the evidence from your system, while the audit and the accreditation stay between you and the competent body. Anyone offering you a “certificate” from us is offering a document with no accreditation value.

    How do we verify a certificate of yours, if one exists?

    In four steps: ask for the certificate number and the issuing body; ask for its exact scope (activity, sites and duration); then check the issuing body’s register where it publishes one; and confirm the validity, expiry and renewal dates. We list those details in the register whenever a certificate exists, and we facilitate any verification a party or client requests. The principle: verifying with the issuing body is stronger than trusting a page — which is what we ask of you towards us, as we apply it to ourselves.

    Will you list “in-progress” certificates?

    No. “In progress” is not a certificate, and listing it grants a meaning it has not reached. If we begin an audit process we will say so in its natural context when discussing work, not in the certifications register as though it were an achievement. The difference is practical: a reader of “in progress” usually understands “obtained” — and that understanding is exactly what we refuse to benefit from.

    Do you publish your clients’ certificates or awards?

    No. A client’s certificate belongs to them and is not published in our name nor used as proof of our work quality, and we publish no client names and no awards we were not formally notified of. If a client wishes to speak about their work with us they do so themselves, and a direct reference arranged with their approval is more useful than a badge that proves nothing.

    What does this page not cover?

    It issues no certificates, manages no accreditation, represents you before no issuing body, substitutes for no formal audit, and is no promise of a protection level or absolute security; and it does not cover your activity licences, operating permits or your clients’ data declarations — all of which are your responsibility. What it contains is our register, the rule we apply to it, our operating controls and the verification path. We say so at assessment stage, before the contract.

    Want evidence rather than a badge?

    Ask for the controls register, a backup restore test report, or a written policy in the scope that matters to you — we will show what exists and say plainly what we have not yet done.

    • An empty register we state rather than hide
    • A control is not called a certification
    • Documentation before handover, not after

    We are a systems implementation and integration company, not a certification body, an audit body or a certificate issuer: we issue no certificates to our clients, manage no accreditation for them and represent them before no issuing body, and we announce no ISO, SOC 2, PCI DSS or other certificate and no “certified partner” or “reseller” status without a fully detailed entry naming an issuing body, a number, a scope and validity dates. Our register is currently empty, and we state that plainly rather than announcing “in-progress” certificates. The controls we operate we call controls rather than accreditations, and we announce no security percentage, no protection level, no market-size figures and no targets, and publish no client certificates or names. Durations shown are planning ranges, not commitments.