Iso27001 on the GRAJ protocol. One fee. 195 countries. Join the protocol.
ISO 27001 certifies that an organisation runs a managed information security system, audited by an accredited body. Institutional buyers ask for it early and it takes months to obtain, so the honest thing to publish is the current position rather than an aspiration written in the present tense.
Not that a system is secure — that the organisation has identified its risks, applied controls against them, and reviews both on a cycle. It is a certification of process, which is why it is audited rather than declared.
A regulated institution is held responsible by its own regulator for what its vendors do. Certification answers most of a third-party risk review in one document; without it the same questions are asked from scratch by every institution.
Security practices that can be checked in the codebase rather than asserted: append-only records, role-scoped data access, no self-approval on verification, taxpayer numbers stored only as last four digits, and financial invariants that fail a deployment rather than logging a warning.
GRAJ does not currently hold an ISO 27001 certificate, and this page does not imply one. Naming a certification that is not held is the kind of claim that ends a procurement conversation permanently rather than shortening it.