Glossary
ISO 27001
ISO/IEC 27001 is the international standard for an information security management system (ISMS): a documented way of assessing risk, selecting controls, and proving the whole thing gets reviewed and improved. A certificate means an accredited body audited that management system within a stated scope, not that a particular product feature is secure.
How it works
The standard itself is short. Clauses 4 to 10 describe the management system: define the scope and the interested parties, run a risk assessment, pick controls, set objectives, train people, measure, audit internally, correct, and have management review it. Annex A then lists the controls you choose from. The current edition, ISO/IEC 27001:2022, reorganized those into 93 controls across four themes: organizational (37), people (8), physical (14) and technological (34), replacing the 114 controls in 14 clauses of the 2013 version. Eleven controls were new, including threat intelligence, information security for cloud services, data masking and secure coding. A 2024 amendment added climate change to the context clauses.
The document that tells you what an organization really does is the statement of applicability. It lists every Annex A control, marks it applicable or not, and justifies the choice. A certificate is one page; the SoA is where the exclusions live.
Certification runs on a three-year cycle: a stage 1 review of documentation, a stage 2 audit of practice, then annual surveillance audits and a full recertification in year three. The auditor must be a certification body accredited under ISO/IEC 17021-1 by a national accreditation body such as COFRAC in France, UKAS in the UK, DAkkS in Germany or ANAB in the US. A certificate issued by an unaccredited consultancy carries no weight. One date check for 2026: certificates against the 2013 version expired at the end of the transition period on 31 October 2025, so anything you're handed now should be a 2022 certificate.
Why it matters for a fleet
What it covers: a management system, inside a scope that the organization wrote itself. What it doesn't cover: the security of a specific feature, the quality of a specific line of code, whether a breach can happen, where your data is hosted, or GDPR compliance, which needs a legal basis and a transfer analysis that ISO 27001 never looks at. SOC 2 is a different animal too, an attestation report from an audit firm rather than a certificate against a standard.
Which is why reading a vendor's claim carefully pays off. Ask for these, in this order:
- Who is certified. The vendor's own legal entity, or only its hosting provider or a subcontractor? Logos on a website often belong to the cloud platform underneath.
- What scope appears on the certificate. It should name the service you are buying and the sites and teams that operate it, not an unrelated business unit.
- The certificate and the statement of applicability. Request the PDF plus the SoA or an extract, and look for excluded controls that matter to you, such as secure development.
- The certification body, and its accreditation. Check it on the accreditation body's register, not on the certificate itself.
- The dates. Issue and expiry, the edition (2022), and whether the latest surveillance audit actually took place.
Ten minutes of that beats a logo in a sales deck. And if a vendor hesitates to share a scope statement, you have learned something.
How Appaloosa handles it
Appaloosa's platform is hosted in France, on infrastructure qualified SecNumCloud and operated by a hosting provider that holds ISO/IEC 27001 certification. That certification belongs to the hosting provider. Appaloosa itself holds no ISO 27001 certificate, and we would rather write that plainly than let a security questionnaire assume otherwise.
What we can document is concrete: where the data sits, which host operates it and under which qualification, the fact that customer data is not transferred outside the EU, and the controls you operate yourself through the console (administrator roles, retention, selective wipe, compliance rules applied to enrolled devices). The product scope is on the mobile device management page.
Book a demo
See Appaloosa run on your fleet
A 20-minute call on your real setup. Enrollment, private apps, security.
Book a demo →See the full platform Explore Appaloosa