Skip to content

ISO 27001

About ISO 27001

ISO 27001 is the international standard for information security management systems (ISMS) — covering risk assessment and treatment, a documented set of security controls, and continual improvement of an organisation's information security posture.

Our Current Position

Aligned with, not certified to, ISO 27001

Agend is not currently certified to ISO 27001 or SOC 2, and has not yet engaged an auditor for either. The information below describes technical and process controls we have in place that align with ISO 27001's control areas — it is not a certification claim.

Controls currently in place, consistent with ISO 27001 Annex A control areas:

  • Tenant data isolation (row-level access control) and role-based access control
  • Multi-factor authentication and enterprise single sign-on (SSO) options
  • Secrets management and application-layer encryption for sensitive credentials
  • Encryption of data in transit (TLS) and at rest
  • API authentication, rate limiting, and abuse-prevention controls (including SSRF protection)
  • Signed, replay-protected webhooks
  • Immutable audit logging and error/anomaly monitoring
  • Data residency and PCI-aligned handling of card data
  • A secure change-management process — code review and automated test gates before every deployment
  • A documented, CTO-owned Information Security Planning and Risk Management Policy, reviewed annually, built around ISO 31000 risk management principles and referencing ISO/IEC 27001:2022 — including a maintained risk register (risk ratings, existing controls, treatment plans) reviewed quarterly by a Security Committee
  • A documented, quarterly-reviewed Security Incident Response Policy covering incident classification, containment/eradication/recovery procedures for specific incident types (data breach, ransomware, DDoS, unauthorised access), and breach notification procedures aligned with the Notifiable Data Breaches (NDB) scheme
  • A documented Business Continuity Plan covering risk assessment, disaster recovery planning, backup and recovery, and incident response
  • A documented annual penetration-testing and vulnerability-scanning schedule (external and internal penetration tests annually; vulnerability scans monthly for critical systems, quarterly for all other systems)
  • Documented, mandatory security-awareness training — delivered during onboarding and refreshed quarterly for all staff, with annual policy acknowledgement required

Known gaps against full ISO 27001 certification, stated plainly:

  • A risk register and risk treatment process exist, but a formal Statement of Applicability and an independent ISMS certification audit have not been completed
  • No SOC 2 report and no auditor currently engaged
  • A documented Business Continuity Plan exists, but specific numeric recovery time/point objectives beyond what we inherit from our infrastructure providers are not yet published externally
  • An annual penetration-testing schedule is documented as policy, but we do not yet have a completed independent penetration test report to publish for Agend Product Suite specifically
  • Security-awareness training is documented and mandatory, but a broader formally documented HR security program (e.g. background-check procedures, role-based security clearance) is not yet published

We are building toward closing these gaps. If a specific control or piece of evidence is required for your organisation's due diligence, please contact security@agend.com.au.

Our infrastructure providers hold relevant independent certifications in their own right — see Data Hosting & Sovereignty for the current sub-processor list and their certifications.