Sudory logo

Sudory

Trust Center

Request access
ISO/IEC 27001 2013 ISO/IEC 27001 2022

Certifications & audits

ISO/IEC 27001:2022Certified

The information security management system supporting the SaaS platform and the corporate functions that operate it.

Certified
1 Mar 2026
Next surveillance
15 Feb 2027

The certificate and Statement of Applicability are in Documents.

Privacy & data protection

Where data is processed

  • European Union (Frankfurt and Ireland)
  • United States (transactional email only)

Transfers: Standard Contractual Clauses for any transfer outside the EEA.

Data Protection Officer: dpo@example.com

The Data Processing Agreement is available on request; subprocessors are listed under Subprocessors.

98 of 114 controls in place 5 continuously verified

A.5 Information security policies

Self-attested

Policies for information security

Self-attested

Review of the policies for information security

A.6 Organization of information security

Self-attested

Information security roles and responsibilities

In progress

Segregation of duties

Self-attested

Contact with authorities

Self-attested

Contact with special interest groups

Self-attested

Information security in project management

Self-attested

Mobile device policy

Self-attested

Teleworking

A.7 Human resource security

Self-attested

Screening

Self-attested

Terms and conditions of employment

Self-attested

Management responsibilities

Self-attested

Information security awareness, education and training

Self-attested

Disciplinary process

Self-attested

Termination or change of employment responsibilities

A.8 Asset management

Self-attested

Inventory of assets

Self-attested

Ownership of assets

Self-attested

Acceptable use of assets

Self-attested

Return of assets

Self-attested

Classification of information

Self-attested

Labelling of information

Self-attested

Handling of assets

Self-attested

Management of removable media

Self-attested

Disposal of media

Self-attested

Physical media transfer

A.9 Access control

Self-attested

Access control policy

Self-attested

Access to networks and network services

In place

User registration and de-registration

In progress

User access provisioning

Self-attested

Management of privileged access rights

In progress

Management of secret authentication information of users

In progress

Review of user access rights

In progress

Removal or adjustment of access rights

In progress

Use of secret authentication information

In progress

Information access restriction

In progress

Secure log-on procedures

In progress

Password management system

Self-attested

Use of privileged utility programs

Self-attested

Access control to program source code

A.10 Cryptography

In progress

Policy on the use of cryptographic controls

In progress

Key management

A.11 Physical and environmental security

Self-attested

Physical security perimeter

Self-attested

Physical entry controls

Self-attested

Securing offices, rooms and facilities

Self-attested

Protecting against external and environmental threats

Self-attested

Working in secure areas

Self-attested

Delivery and loading areas

Self-attested

Equipment siting and protection

Self-attested

Supporting utilities

Self-attested

Cabling security

Self-attested

Equipment maintenance

Self-attested

Removal of assets

Self-attested

Security of equipment and assets off-premises

Self-attested

Secure disposal or reuse of equipment

Self-attested

Unattended user equipment

Self-attested

Clear desk and clear screen policy

A.12 Operations security

Self-attested

Documented operating procedures

In progress

Change management

Self-attested

Capacity management

Self-attested

Separation of development, testing and operational environments

Self-attested

Controls against malware

Self-attested

Information backup

Self-attested

Event logging

Self-attested

Protection of log information

Self-attested

Administrator and operator logs

Self-attested

Clock synchronization

Self-attested

Installation of software on operational systems

Self-attested

Management of technical vulnerabilities

Self-attested

Restrictions on software installation

Self-attested

Information systems audit controls

A.13 Communications security

Self-attested

Network controls

Self-attested

Security of network services

Self-attested

Segregation in networks

In place

Information transfer policies and procedures

In place

Agreements on information transfer

In place

Electronic messaging

Self-attested

Confidentiality or nondisclosure agreements

A.14 System acquisition, development and maintenance

Self-attested

Information security requirements analysis and specification

Self-attested

Securing application services on public networks

Self-attested

Protecting application services transactions

In progress

Secure development policy

In progress

System change control procedures

In progress

Technical review of applications after operating platform changes

In progress

Restrictions on changes to software packages

Self-attested

Secure system engineering principles

Self-attested

Secure development environment

Self-attested

Outsourced development

Self-attested

System security testing

Self-attested

System acceptance testing

Self-attested

Protection of test data

A.15 Supplier relationships

Self-attested

Information security policy for supplier relationships

Self-attested

Addressing security within supplier agreements

Self-attested

Information and communication technology supply chain

Self-attested

Monitoring and review of supplier services

Self-attested

Managing changes to supplier services

A.16 Information security incident management

Self-attested

Responsibilities and procedures

Self-attested

Reporting information security events

Self-attested

Reporting information security weaknesses

Self-attested

Assessment of and decision on information security events

Self-attested

Response to information security incidents

Self-attested

Learning from information security incidents

Self-attested

Collection of evidence

A.17 Information security aspects of business continuity management

Self-attested

Planning information security continuity

Self-attested

Implementing information security continuity

Self-attested

Verify, review and evaluate information security continuity

Self-attested

Availability of information processing facilities

A.18 Compliance

Self-attested

Identification of applicable legislation and contractual requirements

Self-attested

Intellectual property rights

In place

Protection of records

Self-attested

Privacy and protection of personally identifiable information

Self-attested

Regulation of cryptographic controls

Self-attested

Independent review of information security

Self-attested

Compliance with security policies and standards

Self-attested

Technical compliance review