Skip to content
SecurityWorking toward

ISO/IEC 27001 Information Security Management

Desha.ai operates an information-security programme aligned to the ISO/IEC 27001:2022 control set (Annex A) and a risk-based Information Security Management System (ISMS). Formal certification is on our roadmap; today we map our controls to the standard and can share that mapping.

दस्तावेज़ माँगें Last reviewed June 2026
DESHA.AI ट्रस्ट सेंटर

ISO 27001

ISO/IEC 27001 Information Security Management
स्थिति: Working toward
क्षेत्राधिकार: International
समीक्षित: June 2026

एक नज़र में

Standard
ISO/IEC 27001:2022
Controls
93 Annex A controls, 4 themes
Approach
Risk-based ISMS
Certification
Not held; working toward

Information Security Management System

Our ISMS defines security objectives, a risk-assessment and treatment methodology, a Statement of Applicability, and a cycle of review and continual improvement. Security is owned at leadership level.

Annex A control themes

ThemeCoverage
OrganisationalPolicies, roles, supplier security, threat intel, incident management
PeopleScreening, awareness training, responsibilities, joiner/mover/leaver
PhysicalSecure cloud facilities, equipment and media handling
TechnologicalAccess control, cryptography, secure development, logging, backup, vulnerability management

Engineering practices

  • Secure SDLC with code review and dependency/vulnerability scanning.
  • Least-privilege access, MFA, and centralised audit logging.
  • Encryption in transit and at rest; managed key lifecycle.
  • Regular backups with tested restoration and business continuity.
  • Independent penetration testing with remediation tracking, planned.

Honest status

We describe ourselves as “aligned to ISO 27001 controls,” not certified. When certification is achieved the certificate and scope will be published here. Reviewers may request our current control mapping and Statement of Applicability summary under NDA.

दस्तावेज़ अनुरोध पर उपलब्ध

  • ISO 27001 control mapping / Statement of Applicability summary
  • Penetration-test executive summary
  • Information-security policy summary

Provided to qualified reviewers under a mutual NDA via contactus@desha.ai.

यह पेज ड्यू-डिलिजेंस समीक्षा के लिए Desha.ai की स्थिति का सारांश देता है और आंतरिक प्रणालियों या सुरक्षा-संवेदनशील विवरण का खुलासा नहीं करता। यह केवल जानकारी के लिए है, कोई वारंटी या कानूनी सलाह नहीं। अनुबंध की शर्तों के लिए हमारा DPA / BAA यहाँ माँगें contactus@desha.ai.