Skip to content

Security

Information security you can check, not just take our word for

Rubycode is certified to ISO/IEC 27001:2022 by an accredited external auditor. The certificate number below is public, and it is there to be verified.

The certificate

Everything below is printed on the certificate itself, and the body that issued it keeps a public record you can check without going through us.

Standard
ISO/IEC 27001:2022
Certificate number
3850215
Issued by
LL-C (Certification) Czech Republic a.s.
Accreditation
IAF, accreditation S 3137
Scope
Development, implementation, integration and maintenance of application software and other information services
First issued
07 December 2024
Valid until
06 December 2027

What the certification actually means

ISO/IEC 27001 is not a badge you buy. An auditor examines how a company manages information security — how access is granted and taken away, how suppliers are assessed, how incidents are handled — and issues the certificate only if the whole management system stands up to it.

  • Assessed against the full ISO/IEC 27001:2022 standard by LL-C, an accredited certification body working under IAF.
  • Certification runs on a three-year cycle with surveillance audits in between, so it has to be kept rather than won once.
  • The scope covers the work we actually sell — building, integrating and maintaining software — rather than one product line or back-office function.

What your security team can ask us for

The certificate is public. The material behind it is not, because publishing our controls in detail would undermine the reason for having them. We share that directly with clients and prospects instead.

  • Our Statement of Applicability and the detail of the controls behind it, under NDA.
  • Completed security questionnaires and vendor assessments, in whatever format your process uses.
  • A GDPR data processing agreement, plus named contacts for incidents and escalation.
Talk to us about a security review

How we handle personal data is set out in our Privacy Policy.