Skip to content
SecurityWorking toward

ISO/IEC 27001 Information Security Management

Desha.ai operates an information-security programme aligned to the ISO/IEC 27001:2022 control set (Annex A) and a risk-based Information Security Management System (ISMS). Formal certification is on our roadmap; today we map our controls to the standard and can share that mapping.

Solicitar documentación Last reviewed June 2026
Centro de confianza de DESHA.AI

ISO 27001

ISO/IEC 27001 Information Security Management
Estado: Working toward
Jurisdicción: International
Revisado: June 2026

De un vistazo

Standard
ISO/IEC 27001:2022
Controls
93 Annex A controls, 4 themes
Approach
Risk-based ISMS
Certification
Not held; working toward

Information Security Management System

Our ISMS defines security objectives, a risk-assessment and treatment methodology, a Statement of Applicability, and a cycle of review and continual improvement. Security is owned at leadership level.

Annex A control themes

ThemeCoverage
OrganisationalPolicies, roles, supplier security, threat intel, incident management
PeopleScreening, awareness training, responsibilities, joiner/mover/leaver
PhysicalSecure cloud facilities, equipment and media handling
TechnologicalAccess control, cryptography, secure development, logging, backup, vulnerability management

Engineering practices

  • Secure SDLC with code review and dependency/vulnerability scanning.
  • Least-privilege access, MFA, and centralised audit logging.
  • Encryption in transit and at rest; managed key lifecycle.
  • Regular backups with tested restoration and business continuity.
  • Independent penetration testing with remediation tracking, planned.

Honest status

We describe ourselves as “aligned to ISO 27001 controls,” not certified. When certification is achieved the certificate and scope will be published here. Reviewers may request our current control mapping and Statement of Applicability summary under NDA.

Documentación disponible bajo petición

  • ISO 27001 control mapping / Statement of Applicability summary
  • Penetration-test executive summary
  • Information-security policy summary

Provided to qualified reviewers under a mutual NDA via contactus@desha.ai.

Esta página resume la posición de Desha.ai para revisiones de diligencia debida y no revela sistemas internos ni detalles sensibles para la seguridad. Es informativa y no constituye garantía ni asesoramiento jurídico. Para las condiciones contractuales, solicita nuestro DPA / BAA en contactus@desha.ai.