Trust & Security

We hold ourselves to the same standards
we implement for you.

Protectify AI is ISO 27001 certified. Our information security management system is independently audited annually. Here is what that means for you and your data.

๐Ÿ›ก๏ธ

Protectify AI is ISO 27001 certified

Our Information Security Management System (ISMS) has been independently assessed by an accredited certification body and meets the requirements of ISO/IEC 27001:2022 โ€” the internationally recognised standard for information security.

ISO/IEC 27001:2022 Certified

What our ISO 27001 certification covers

ISO 27001 is not a self-assessment. It requires independent, accredited audit of your security programme โ€” covering people, processes, and technology. Our certification confirms that we:

Our security commitments

๐Ÿ”

Access control

Access to client information is restricted on a strict need-to-know basis with role-based controls and regular access reviews.

๐Ÿ“‹

Confidentiality

All team members are bound by confidentiality obligations. Client data is never shared without explicit written consent.

๐Ÿ””

Incident response

We maintain a documented incident response programme. In the event of any security incident affecting client data, we will notify you promptly.

๐Ÿข

Supplier management

We assess the security posture of our technology suppliers and ensure appropriate contractual protections are in place.

๐Ÿ“Š

Risk management

We conduct formal risk assessments at least annually and maintain a risk register that feeds into our control selection and improvement activities.

๐Ÿ”„

Continual improvement

Our ISMS is a living system. We review and improve our controls in response to internal audits, surveillance findings, and the evolving threat landscape.

Key policies in place

โœ“
Information Security Policy
โœ“
Access Control & Password Policy
โœ“
Incident Response Policy
โœ“
Risk Assessment & Treatment Policy
โœ“
Vendor & Supplier Management Policy
โœ“
Data Classification & Handling Policy
โœ“
Business Continuity & Disaster Recovery Policy
โœ“
Acceptable Use Policy

Data protection

We are registered in England and Wales and process personal data in accordance with UK GDPR and the Data Protection Act 2018. Our Privacy Policy details exactly what data we collect, how we use it, and your rights as a data subject.

We do not sell personal data to third parties. We do not use tracking cookies or advertising technologies on this website. Client engagement data is held only for the duration required to fulfil our services and legal obligations.

Questions or security concerns

If you have a security concern, vulnerability disclosure, or question about our information security practices, please contact us directly at support@protectifyai.com. We take all security reports seriously and will respond within two business days.

Want to see what we'd implement for your business?

Bring your current compliance gaps to a 45-minute working session.

Book a working session โ†’