ISOXPERT Compliance360 Back to Compliance360

Trust & Security

How your management-system data is handled

Compliance360 holds the records an auditor will one day inspect. This page sets out the controls that protect them, who is responsible for what, and — just as importantly — the things we do not claim.

← Back to the platform
What this page is. A description of implemented technical and organizational controls, and of who is responsible for what. ISOXPERT operates an ISO/IEC 27001-certified information security management system covering the development and operation of Compliance360; we do not hold a SOC 2 report. Where a control is provided by an underlying platform rather than built by us, we say so, and where an outcome depends on how you operate your own system, we say that too.

0. Certification

ISOXPERT's information security management system is certified to ISO/IEC 27001. The certificate scope covers the development and operation of Compliance360 — that is, the service this page describes, not a separate part of the business.

The certificate, its scope statement and the current validity dates are provided on request for your supplier assessment or due-diligence questionnaire — ask sales@isoxpert.com.

Who issued the certificate, and why we tell you unprompted. The certificate was issued by Company Certification International (CCI). ISOXPERT is a separate organization, but it is under common ownership with CCI — so CCI is a related certification body, not an unconnected one. We would rather you read that here than discover it on the certificate during your assessment.

What that means for you, stated plainly:

Certification means a management system has been audited against the standard. It is not a guarantee about any individual control, and it does not make your organization compliant — sections 12 and 14 set out what remains yours.

1. Who operates the service, hosting and data regions

ISOXPERT is an independent consulting and technology firm under common ownership with Company Certification International (CCI), and the development and operations house for Compliance360, based in Karachi, Pakistan. CCI's certification and audit services are provided under separate arrangements and are not part of this service — see section 15.

The application and its serverless API functions are hosted on Vercel. Application data — accounts, organization setup, documents, audits, risks, CAPAs, evidence and audit logs — is stored in a dedicated Supabase (PostgreSQL) project managed by ISOXPERT, together with private object storage for uploaded evidence and documents.

International transfers. Our operating entity is established in Pakistan, which is not covered by an EU or UK adequacy decision. Access by our engineering and support staff to personal data relating to EEA, UK or GCC data subjects is therefore an international transfer in its own right, in addition to the sub-processors in section 9. The mechanism that applies to your contract — in practice Standard Contractual Clauses with a transfer impact assessment — is set out in our Data Processing Agreement.

The specific hosting region for your data is confirmed in writing before contract and recorded in the Data Processing Agreement. Ask sales@isoxpert.com for the current region statement.

2. Encryption

3. Tenant isolation

Isolation is enforced in the database, not in application code. Every tenant table carries PostgreSQL Row-Level Security policies scoped to the requesting user's organization, so a query that forgets a filter returns nothing rather than another customer's records. Uploaded files are isolated on the object key, so a signed URL for one organization cannot address another's evidence.

Platform-administrator access is a distinct, explicitly-granted capability used for catalog and support operations; it is not the default state of any customer account.

4. Authentication and SSO

SAML and SCIM provisioning are not currently supported. If your organization requires them, tell us before you buy rather than after.

5. Role-based access

Permissions are role-based and enforced at both the interface and the database. Roles determine who may create records, who may review, and who may approve or close them — which is what makes an approval mean something when an auditor asks who authorized a document.

Your subscription additionally determines which modules and standards are available to your workspace; access control and entitlement are separate mechanisms and are evaluated independently.

6. Audit logging

Record changes are written to an append-only change log — entries cannot be edited or deleted from the application. Electronic approvals additionally capture the signer, the meaning of the signature, the timestamp and a cryptographic hash of the signed content.

7. Backup and recovery

The database platform performs automated backups of the managed PostgreSQL instance. Restores are performed by ISOXPERT on request as part of support.

We do not currently publish a contractual RTO or RPO. If your business continuity programme requires stated recovery targets, request them in writing before contract so they can be agreed rather than assumed.

8. Data retention and deletion

Personal data is retained only as long as necessary for the purposes set out in the Privacy Policy and to meet legal and audit obligations. Compliance and audit records may be retained for a statutory period after an account closes; where a record must be kept for audit integrity we pseudonymize in preference to deleting it.

Data subject access requests are supported by a one-click export, and consent records are captured in the application. Full details, including the lawful bases we rely on, are in the Privacy Policy.

9. Subprocessors

The third parties that process data on our behalf — hosting, database and authentication, AI, and billing — are listed, with their purpose and data categories, on the Sub-processors page. Customers are notified before a new subprocessor is added.

On AI specifically: content you submit to AI features is sent to the model provider's paid API, which does not use that content to train its models. AI never writes to your controlled records on its own — see section 12.

10. Data-processing terms

For personal data your organization uploads about its employees, suppliers and customers, ISOXPERT acts as a processor and your organization is the controller. Our Data Processing Agreement covers subprocessor terms, security measures, breach notification, and assistance with data subject requests and DPIAs. Request the current DPA from sales@isoxpert.com.

11. Incident response and business continuity

Security incidents affecting customer data are notified to account administrators, and to controllers within the timeframe set out in the DPA. Service availability depends on our hosting and database providers, whose own redundancy and status reporting apply.

We do not operate a 24/7 security operations centre, and we do not claim one.

12. Your responsibilities — please read this one

Compliance360 provides controls. Whether your use of those controls satisfies a particular regulation is a determination only your organization can make. In particular:

AreaWhat we provideWhat remains yours
Electronic signatures Approvals bound to a SHA-256 hash of the signed record, requiring re-authentication, with signer, meaning and timestamp captured and a printable signature manifest. Validation of the system for your intended use, your own SOPs, training records and the determination that the configuration meets 21 CFR Part 11, EU Annex 11 or your applicable rule. We do not supply a validation package, and we do not claim the product is "Part 11 compliant" out of the box.
AI-assisted drafting Drafts grounded in your organization setup, scope, processes and selected standards. Review, adaptation, approval and technical accuracy. A draft is not a controlled document until an authorized reviewer approves it through your workflow.
Documentation framework A tailored, clause-mapped set of policies, procedures, SOPs and record templates. Implementation, competence and awareness, operating records, monitoring, internal audit, corrective action and management review — everything that turns documents into a working, auditable system.
Access and roles Role-based permissions, approval routing and tenant isolation. Assigning the right roles to the right people, and removing access when someone leaves.
Regulatory determination Registers, applicability decisions, evaluation schedules and evidence linking. Deciding which obligations apply to you, and whether you meet them.

13. Data export and portability

Documents and records export to Word, Excel and PDF at any time, from within the application, including after you cancel. There is no export fee and no retention hostage: if you leave, you leave with your management system.

14. What we do not claim

If any statement on this page conflicts with your contract, the contract governs.

15. Our relationship with CCI, and why it does not affect your certification

ISOXPERT is an independent consulting and technology firm under common ownership with Company Certification International (CCI), a certification body accredited by International Accreditation Registrar (IAR), USA — accreditation No. IAR-112. We disclose this rather than leave you to find it, because if your organization is certified by CCI — or is considering it — you are entitled to know before you buy. The same disclosure is published group-wide, including at isoxpert.com/governance.html.

The two are deliberately separate:

Certification bodies operate under impartiality requirements (ISO/IEC 17021-1) that govern their relationships with related entities and restrict management-system consultancy to organizations they certify. Those arrangements are CCI's to operate and evidence — its published safeguards are at companycertification.com/impartiality-and-independence; if your assessment needs them in writing, request CCI's impartiality statement directly and we will help you get it.

Questions

Security, privacy and due-diligence questionnaires: sales@isoxpert.com. We would rather answer a hard question before you buy than have you discover the answer during your own certification audit.