Skip to main content

Glossary

ISO 27001

ISO/IEC 27001 is the international standard for an information security management system (ISMS): a documented way of assessing risk, selecting controls, and proving the whole thing gets reviewed and improved. A certificate means an accredited body audited that management system within a stated scope, not that a particular product feature is secure.

How it works

The standard itself is short. Clauses 4 to 10 describe the management system: define the scope and the interested parties, run a risk assessment, pick controls, set objectives, train people, measure, audit internally, correct, and have management review it. Annex A then lists the controls you choose from. The current edition, ISO/IEC 27001:2022, reorganized those into 93 controls across four themes: organizational (37), people (8), physical (14) and technological (34), replacing the 114 controls in 14 clauses of the 2013 version. Eleven controls were new, including threat intelligence, information security for cloud services, data masking and secure coding. A 2024 amendment added climate change to the context clauses.

The document that tells you what an organization really does is the statement of applicability. It lists every Annex A control, marks it applicable or not, and justifies the choice. A certificate is one page; the SoA is where the exclusions live.

Certification runs on a three-year cycle: a stage 1 review of documentation, a stage 2 audit of practice, then annual surveillance audits and a full recertification in year three. The auditor must be a certification body accredited under ISO/IEC 17021-1 by a national accreditation body such as COFRAC in France, UKAS in the UK, DAkkS in Germany or ANAB in the US. A certificate issued by an unaccredited consultancy carries no weight. One date check for 2026: certificates against the 2013 version expired at the end of the transition period on 31 October 2025, so anything you're handed now should be a 2022 certificate.

Why it matters for a fleet

What it covers: a management system, inside a scope that the organization wrote itself. What it doesn't cover: the security of a specific feature, the quality of a specific line of code, whether a breach can happen, where your data is hosted, or GDPR compliance, which needs a legal basis and a transfer analysis that ISO 27001 never looks at. SOC 2 is a different animal too, an attestation report from an audit firm rather than a certificate against a standard.

Which is why reading a vendor's claim carefully pays off. Ask for these, in this order:

  • Who is certified. The vendor's own legal entity, or only its hosting provider or a subcontractor? Logos on a website often belong to the cloud platform underneath.
  • What scope appears on the certificate. It should name the service you are buying and the sites and teams that operate it, not an unrelated business unit.
  • The certificate and the statement of applicability. Request the PDF plus the SoA or an extract, and look for excluded controls that matter to you, such as secure development.
  • The certification body, and its accreditation. Check it on the accreditation body's register, not on the certificate itself.
  • The dates. Issue and expiry, the edition (2022), and whether the latest surveillance audit actually took place.

Ten minutes of that beats a logo in a sales deck. And if a vendor hesitates to share a scope statement, you have learned something.

How Appaloosa handles it

Appaloosa's platform is hosted in France, on infrastructure qualified SecNumCloud and operated by a hosting provider that holds ISO/IEC 27001 certification. That certification belongs to the hosting provider. Appaloosa itself holds no ISO 27001 certificate, and we would rather write that plainly than let a security questionnaire assume otherwise.

What we can document is concrete: where the data sits, which host operates it and under which qualification, the fact that customer data is not transferred outside the EU, and the controls you operate yourself through the console (administrator roles, retention, selective wipe, compliance rules applied to enrolled devices). The product scope is on the mobile device management page.

Book a demo

See Appaloosa run on your fleet

A 20-minute call on your real setup. Enrollment, private apps, security.

Book a demo

See the full platform Explore Appaloosa

Frequently asked questions

Is Appaloosa ISO 27001 certified?
No. The hosting provider that operates the infrastructure in France holds that certification, and the infrastructure is also qualified SecNumCloud. The certificate is the host's, not Appaloosa's. If a questionnaire asks for a vendor certificate, say so and attach the hosting documentation instead of a claim that would not survive an audit.
A vendor shows an ISO 27001 logo. What should I check?
Whether the certified entity is the vendor or its cloud provider, what scope is written on the certificate, which body issued it and whether that body is accredited, and the validity dates. Then ask for the statement of applicability and look at the excluded controls. A scope covering one office and not the service you buy is common.
Does ISO 27001 certification mean a vendor is GDPR compliant?
No. The standard audits a management system and says nothing about legal basis, data subject rights, or transfers outside the EU. ISO 27701 extends it toward privacy and is closer to what you want, but a GDPR assessment still needs the hosting location, the subprocessor list and the transfer mechanism.