Back to Trust Center
Certification standard
ISO 27001
CertifiedAssurance details maintained by Qorelo GmbH for customer and partner review.
View supporting evidencePublic disclosures
Security information
Policy titles shared publicly. Approved users can download the published policy PDFs.
Acceptable Use & Workstation Security
Access Control & Least Privilege
Authentication & Password
Background Screening & On/Off-boarding
Backup, Business Continuity & Disaster Recovery
Change & Release Management
Code of Business Conduct
Compliance & Regulatory Monitoring
Data Classification & Handling
Data Subject Request Workflow
Encryption & Crypto Controls
Incident Response & Breach Notification
Information Security Objectives
Information Security Policy
Information Sharing & Transfer
Internal Audit Procedure
ISMS Change Management Procedure
ISMS Communication Plan
ISMS Monitoring & Measurement Plan
Logging, Monitoring & Audit
Management Review Procedure
Nonconformity & Corrective Action Procedure
Physical Security & Environmental
Policy Management & Exception Handling
Remote Access & BYOD
Retention & Secure Disposal
Risk Management
Sanctions & Disciplinary
Secure Configuration & Hardening
Secure Software Development Lifecycle
Security & Privacy Awareness Training
Vendor & Third-Party Risk
Vulnerability & Patch Management
Third parties that process data on the organization’s behalf.
AWS Amazon Web Services is a comprehensive and widely adopted cloud platform, offering over 200 fully featured services from data centers globally.
SOC 2ISO 27001ISO 42001PCI DSSHIPAAGDPR
GitHub GitHub is a provider of Internet hosting for software development and version control using Git.
SOC 2ISO 27001PCI DSSGDPR
OpenAI, Inc. LLM provider, Zero Data Retention, EU Residency
SOC 2ISO 27001ISO 42001PCI DSSHIPAAGDPR
Security safeguards published for customer and partner review.
Acceptable Use
Access Rights
Asset Inventory
Change management
Configuration & Patch Management
Credential Management
Data Masking
Data Privacy
Data Retention & Destruction
Disaster Recovery Planning
Disciplinary process
Encrypted Data at Rest
Encryption Key Management
Endpoint Protection
Endpoint Security
GDPR
Information Classification
ISO
Management Security Accountability
Network Security
Organization Structure & Reporting Lines
Personnel Security
Physical Access Control
Policy Compliance
Regulatory Liaison
Remote-Work Security
Resource Capacity Management
Risk Management
Secure Data Transfer
Secure SDLC Integration
Security Governance Roles
Security Incident Management
Security Logging
Security Monitoring & Detection
Segregation of duties
Standard Operating Procedures (SOPs)
Supplier Security
Utility Tool monitoring
Vulnerability Management
Security reports and supporting materials listed for controlled sharing. Request approval to open restricted files.
QORELO GMBH ISO27001 CERTIFICATE.pdf Updated Aug 26, 2026
NDA required