0. Certification
ISOXPERT's information security management system is certified to ISO/IEC 27001. The certificate scope covers the development and operation of Compliance360 — that is, the service this page describes, not a separate part of the business.
The certificate, its scope statement and the current validity dates are provided on request for your supplier assessment or due-diligence questionnaire — ask sales@isoxpert.com.
Who issued the certificate, and why we tell you unprompted. The certificate was issued by Company Certification International (CCI). ISOXPERT is a separate organization, but it is under common ownership with CCI — so CCI is a related certification body, not an unconnected one. We would rather you read that here than discover it on the certificate during your assessment.
What that means for you, stated plainly:
- Treat this certification as evidence that a management system exists and has been audited against ISO/IEC 27001 — not as independent third-party assurance in the way a certificate from an unconnected body would be.
- If your procurement or risk process requires certification from a body with no relationship to the supplier, this certificate will not satisfy it, and you should say so early rather than late.
- You are entitled to ask CCI for its accreditation status and its impartiality analysis covering this certification — CCI publishes its impartiality safeguards at companycertification.com/impartiality-and-independence. Ask us and we will put the request through.
Certification means a management system has been audited against the standard. It is not a guarantee about any individual control, and it does not make your organization compliant — sections 12 and 14 set out what remains yours.
1. Who operates the service, hosting and data regions
ISOXPERT is an independent consulting and technology firm under common ownership with Company Certification International (CCI), and the development and operations house for Compliance360, based in Karachi, Pakistan. CCI's certification and audit services are provided under separate arrangements and are not part of this service — see section 15.
The application and its serverless API functions are hosted on Vercel. Application data — accounts, organization setup, documents, audits, risks, CAPAs, evidence and audit logs — is stored in a dedicated Supabase (PostgreSQL) project managed by ISOXPERT, together with private object storage for uploaded evidence and documents.
International transfers. Our operating entity is established in Pakistan, which is not covered by an EU or UK adequacy decision. Access by our engineering and support staff to personal data relating to EEA, UK or GCC data subjects is therefore an international transfer in its own right, in addition to the sub-processors in section 9. The mechanism that applies to your contract — in practice Standard Contractual Clauses with a transfer impact assessment — is set out in our Data Processing Agreement.
The specific hosting region for your data is confirmed in writing before contract and recorded in the Data Processing Agreement. Ask sales@isoxpert.com for the current region statement.
2. Encryption
- In transit. All traffic is served over HTTPS/TLS, with HTTP Strict Transport Security enabled so browsers refuse to downgrade to plain HTTP.
- At rest. Database and object storage are encrypted at rest by the underlying managed platform.
- Secrets. API keys and service credentials are held server-side only, in the hosting platform's encrypted environment store. They are never shipped to the browser — AI calls, billing calls and privileged database operations all run through server-side functions for this reason.
3. Tenant isolation
Isolation is enforced in the database, not in application code. Every tenant table carries PostgreSQL Row-Level Security policies scoped to the requesting user's organization, so a query that forgets a filter returns nothing rather than another customer's records. Uploaded files are isolated on the object key, so a signed URL for one organization cannot address another's evidence.
Platform-administrator access is a distinct, explicitly-granted capability used for catalog and support operations; it is not the default state of any customer account.
4. Authentication and SSO
- Email and password authentication, with password-strength feedback at sign-up.
- Google SSO (Google Workspace accounts) via OAuth.
- Sessions are managed by the authentication platform, with token refresh handled in the browser.
- Signing out clears locally cached data on that device, including the offline read cache and pending write queue, so a shared machine does not retain the previous user's records.
SAML and SCIM provisioning are not currently supported. If your organization requires them, tell us before you buy rather than after.
5. Role-based access
Permissions are role-based and enforced at both the interface and the database. Roles determine who may create records, who may review, and who may approve or close them — which is what makes an approval mean something when an auditor asks who authorized a document.
Your subscription additionally determines which modules and standards are available to your workspace; access control and entitlement are separate mechanisms and are evaluated independently.
6. Audit logging
Record changes are written to an append-only change log — entries cannot be edited or deleted from the application. Electronic approvals additionally capture the signer, the meaning of the signature, the timestamp and a cryptographic hash of the signed content.
7. Backup and recovery
The database platform performs automated backups of the managed PostgreSQL instance. Restores are performed by ISOXPERT on request as part of support.
We do not currently publish a contractual RTO or RPO. If your business continuity programme requires stated recovery targets, request them in writing before contract so they can be agreed rather than assumed.
8. Data retention and deletion
Personal data is retained only as long as necessary for the purposes set out in the Privacy Policy and to meet legal and audit obligations. Compliance and audit records may be retained for a statutory period after an account closes; where a record must be kept for audit integrity we pseudonymize in preference to deleting it.
Data subject access requests are supported by a one-click export, and consent records are captured in the application. Full details, including the lawful bases we rely on, are in the Privacy Policy.
9. Subprocessors
The third parties that process data on our behalf — hosting, database and authentication, AI, and billing — are listed, with their purpose and data categories, on the Sub-processors page. Customers are notified before a new subprocessor is added.
On AI specifically: content you submit to AI features is sent to the model provider's paid API, which does not use that content to train its models. AI never writes to your controlled records on its own — see section 12.
10. Data-processing terms
For personal data your organization uploads about its employees, suppliers and customers, ISOXPERT acts as a processor and your organization is the controller. Our Data Processing Agreement covers subprocessor terms, security measures, breach notification, and assistance with data subject requests and DPIAs. Request the current DPA from sales@isoxpert.com.
11. Incident response and business continuity
Security incidents affecting customer data are notified to account administrators, and to controllers within the timeframe set out in the DPA. Service availability depends on our hosting and database providers, whose own redundancy and status reporting apply.
We do not operate a 24/7 security operations centre, and we do not claim one.
12. Your responsibilities — please read this one
Compliance360 provides controls. Whether your use of those controls satisfies a particular regulation is a determination only your organization can make. In particular:
| Area | What we provide | What remains yours |
|---|---|---|
| Electronic signatures | Approvals bound to a SHA-256 hash of the signed record, requiring re-authentication, with signer, meaning and timestamp captured and a printable signature manifest. | Validation of the system for your intended use, your own SOPs, training records and the determination that the configuration meets 21 CFR Part 11, EU Annex 11 or your applicable rule. We do not supply a validation package, and we do not claim the product is "Part 11 compliant" out of the box. |
| AI-assisted drafting | Drafts grounded in your organization setup, scope, processes and selected standards. | Review, adaptation, approval and technical accuracy. A draft is not a controlled document until an authorized reviewer approves it through your workflow. |
| Documentation framework | A tailored, clause-mapped set of policies, procedures, SOPs and record templates. | Implementation, competence and awareness, operating records, monitoring, internal audit, corrective action and management review — everything that turns documents into a working, auditable system. |
| Access and roles | Role-based permissions, approval routing and tenant isolation. | Assigning the right roles to the right people, and removing access when someone leaves. |
| Regulatory determination | Registers, applicability decisions, evaluation schedules and evidence linking. | Deciding which obligations apply to you, and whether you meet them. |
13. Data export and portability
Documents and records export to Word, Excel and PDF at any time, from within the application, including after you cancel. There is no export fee and no retention hostage: if you leave, you leave with your management system.
14. What we do not claim
- We hold no SOC 2 report. Our ISO/IEC 27001 certification (section 0) covers our information security management system — it is not a substitute for a SOC 2 attestation if your procurement process specifically requires one.
- We do not claim that using Compliance360 makes an organization compliant, certified or audit-ready. Those outcomes depend on how you operate your system.
- We do not claim a validated 21 CFR Part 11 system. We provide electronic-signature controls designed to support regulated approval workflows.
- We do not publish customer names, logos, testimonials or implementation counts we cannot evidence.
If any statement on this page conflicts with your contract, the contract governs.
15. Our relationship with CCI, and why it does not affect your certification
ISOXPERT is an independent consulting and technology firm under common ownership with Company Certification International (CCI), a certification body accredited by International Accreditation Registrar (IAR), USA — accreditation No. IAR-112. We disclose this rather than leave you to find it, because if your organization is certified by CCI — or is considering it — you are entitled to know before you buy. The same disclosure is published group-wide, including at isoxpert.com/governance.html.
The two are deliberately separate:
- Compliance360 makes no certification decisions. There is no certificate issuance, no certification-body technical review and no certification lifecycle in this product. It is software for running your management system.
- Using Compliance360 is not a route to certification and confers no advantage in one. Buying, using or not using this product has no bearing on any certification decision, and your auditor will assess your management system on its own evidence exactly as they would otherwise.
- You do not have to be a CCI client to use Compliance360, and using Compliance360 does not make you one. Most customers are certified by other bodies, or not yet certified at all.
Certification bodies operate under impartiality requirements (ISO/IEC 17021-1) that govern their relationships with related entities and restrict management-system consultancy to organizations they certify. Those arrangements are CCI's to operate and evidence — its published safeguards are at companycertification.com/impartiality-and-independence; if your assessment needs them in writing, request CCI's impartiality statement directly and we will help you get it.
Questions
Security, privacy and due-diligence questionnaires: sales@isoxpert.com. We would rather answer a hard question before you buy than have you discover the answer during your own certification audit.