EXPLOREINDUSTRIESGUIDESLEARNGLOSSARYBOOKSWHITEPAPERTOOLSRESOURCESPIONEERMARKETSCOUNTRIESFEESMISSION FUNDPASSPORT
SUPPORTLOGINJOIN THE PROTOCOL →
GETREADYANDJUMP.COM · BUILT IN DETROIT

ISO27001
ON GRAJ.

Iso27001 on the GRAJ protocol. One fee. 195 countries. Join the protocol.

JOIN THE PROTOCOL →
Security

ISO 27001,
AND WHERE WE ARE.

Being built

ISO 27001 certifies that an organisation runs a managed information security system, audited by an accredited body. Institutional buyers ask for it early and it takes months to obtain, so the honest thing to publish is the current position rather than an aspiration written in the present tense.

What the standard actually certifies

Not that a system is secure — that the organisation has identified its risks, applied controls against them, and reviews both on a cycle. It is a certification of process, which is why it is audited rather than declared.

Why buyers ask for it

A regulated institution is held responsible by its own regulator for what its vendors do. Certification answers most of a third-party risk review in one document; without it the same questions are asked from scratch by every institution.

What is genuinely in place

Security practices that can be checked in the codebase rather than asserted: append-only records, role-scoped data access, no self-approval on verification, taxpayer numbers stored only as last four digits, and financial invariants that fail a deployment rather than logging a warning.

What is not

GRAJ does not currently hold an ISO 27001 certificate, and this page does not imply one. Naming a certification that is not held is the kind of claim that ends a procurement conversation permanently rather than shortening it.

Where to go next
/pentest/disaster-recovery/guides/financial-services-industry/security
JOIN THE PROTOCOL