Security
Information security you can check, not just take our word for
Rubycode is certified to ISO/IEC 27001:2022 by an accredited external auditor. The certificate number below is public, and it is there to be verified.
The certificate
Everything below is printed on the certificate itself, and the body that issued it keeps a public record you can check without going through us.
- Standard
- ISO/IEC 27001:2022
- Certificate number
- 3850215
- Issued by
- LL-C (Certification) Czech Republic a.s.
- Accreditation
- IAF, accreditation S 3137
- Scope
- Development, implementation, integration and maintenance of application software and other information services
- First issued
- 07 December 2024
- Valid until
- 06 December 2027
What the certification actually means
ISO/IEC 27001 is not a badge you buy. An auditor examines how a company manages information security — how access is granted and taken away, how suppliers are assessed, how incidents are handled — and issues the certificate only if the whole management system stands up to it.
- Assessed against the full ISO/IEC 27001:2022 standard by LL-C, an accredited certification body working under IAF.
- Certification runs on a three-year cycle with surveillance audits in between, so it has to be kept rather than won once.
- The scope covers the work we actually sell — building, integrating and maintaining software — rather than one product line or back-office function.
What your security team can ask us for
The certificate is public. The material behind it is not, because publishing our controls in detail would undermine the reason for having them. We share that directly with clients and prospects instead.
- Our Statement of Applicability and the detail of the controls behind it, under NDA.
- Completed security questionnaires and vendor assessments, in whatever format your process uses.
- A GDPR data processing agreement, plus named contacts for incidents and escalation.
How we handle personal data is set out in our Privacy Policy.