| Control | Status |
|---|---|
|
Infrastructure managed as code
All server, network and access configuration is defined as code and changed only through reviewed merge requests — no manual changes to production.
|
|
|
Privileged access controlled and logged
Access to production systems is least-privilege and requires multi-factor authentication; direct root login is prevented and all privileged activity is logged.
|
|
|
Environments and tenants isolated
Development, staging, demo and production run in separate, isolated networks, and each customer is isolated in its own tenant.
|
|
|
Production data backed up
Production data is backed up automatically — continuous incremental plus regular full backups — and stored encrypted, off-site and geo-redundant, separate from production.
|
|
|
Backups restore-tested
Backups are restore-tested automatically on a regular basis to confirm they actually recover.
|
|
|
Database redundancy maintained
A delayed standby database replica and real-time change streaming provide redundancy and fast recovery.
|
|
|
Physical security enforced
Offices and the server room use layered physical perimeters, escorted visitors, lockable storage, clear-desk/clear-screen, and regularly reviewed access registers.
|
|
|
Assets inventoried and owned
Information assets, devices and infrastructure are inventoried with assigned owners and lifecycle controls.
|
| Control | Status |
|---|---|
|
Security awareness training
All staff complete security-awareness training at onboarding and at least once a year, with completion tracked.
|
|
|
Roles and responsibilities defined
Information-security roles and responsibilities are formally defined, from the Board and CISO down to every employee.
|
|
|
Competence managed
Required security competencies per role are defined in a competency register, and gaps are closed through training, mentoring or hiring.
|
|
|
Personnel screening
Staff are background-screened before engagement, proportional to role sensitivity.
|
|
|
Confidentiality agreements
Confidentiality / non-disclosure terms are signed before access to information is granted.
|
|
|
Supplier security governed
Suppliers are risk-assessed before onboarding and bound by contractual security and privacy clauses, including breach notification and secure deletion on exit.
|
| Control | Status |
|---|---|
|
Risk assessment performed
ioki runs a documented, ISO 27005-aligned risk-management process: risks are identified, scored, treated and reviewed on a defined cadence, including an annual risk workshop.
|
|
|
Incident response process
A documented incident-response process (detect, triage, contain, fix, notify, post-mortem) runs with 24/7 on-call escalation.
|
|
|
Incident communication
During incidents, internal and external stakeholders — and, where required, regulators within 72 hours — are notified through defined channels.
|
|
|
ISMS effectiveness monitored
The information security management system is monitored and measured against defined pass/fail criteria across all control areas.
|
|
|
Independent internal audit
The ISMS is independently internally audited on a program that mirrors the certification body, with findings tracked to closure.
|
|
|
Change management
Every change is ticketed, risk-classified and four-eyes reviewed; high-impact changes require committee approval, and emergency changes get post-incident review.
|
| Control | Status |
|---|---|
|
AI acceptable-use policy
ioki maintains an AI policy: only approved enterprise AI tools are allowed, personal data and secrets must never be entered, and consumer AI accounts are prohibited.
|
|
|
EU AI Act classification assessed
ioki has assessed and documents its EU AI Act classification and re-confirms it at least annually.
|
| Control | Status |
|---|---|
|
Penetration testing
The platform is penetration-tested at least annually, and findings are fixed on severity-based timelines.
|
|
|
Encryption in transit and at rest
Data is encrypted in transit using TLS (1.3 internally; 1.2 or higher for public endpoints) and at rest using strong, industry-standard algorithms such as AES-256, with managed keys.
|
|
|
Vulnerability management
Vulnerabilities are continuously scanned, triaged daily, and patched on SLA (critical issues within 24 hours).
|
|
|
Security logging and monitoring
Systems emit centralized, tamper-resistant logs and metric-driven alerts that route to 24/7 on-call.
|
|
|
Secure software development
Software is built secure-by-default: version control with four-eyes review, automated security gates (SAST/SCA/secret scanning), and separated environments.
|
| Control | Status |
|---|---|
|
Privacy and PII protection
ioki processes personal data under the GDPR, with a Data Protection Liaison, data processing agreements with processors, a records-of-processing register and a DPIA process.
|
|
|
Information classification
All information is classified into defined levels (Public, Internal, Confidential, Strictly Confidential) with handling rules per level.
|
|
|
Retention and secure deletion rules
Data is retained only as long as needed and disposed of securely under defined retention and deletion rules.
|
|
|
Data deletion on request
Personal data is deleted on request: business customers can trigger deletion through configurable automated platform functions, and employee data is handled through defined HR processes.
|
|
|
Business continuity and disaster recovery
ioki maintains a Business Continuity Policy and a tested Disaster Recovery Plan covering scenarios such as cloud-provider loss, database corruption and ransomware.
|
|
|
Disaster recovery tested annually
The Disaster Recovery Plan is tested at least annually, and on significant change, with results documented and remediated.
|