How does ISO 27001 differ from SOC 2?
ISO 27001 certifies a company's entire management system for security, proving a holistic process is in place. SOC 2 is an attestation report that audits the effectiveness of specific controls against defined criteria. They are complementary, and Stacksync maintains both to provide comprehensive assurance.
What is the scope of Stacksync's ISO 27001 certification?
Our ISO 27001 certification covers the people, processes, and technology that support the delivery of the entire Stacksync data integration platform. The official Statement of Applicability is available for review.
How does Stacksync maintain its ISO 27001 certification?
We maintain our certification through a cycle of continuous improvement. This includes regular internal audits, management reviews of the ISMS, and an annual external surveillance audit conducted by our certification body.
How does using Stacksync help with my own company's compliance audits?
Using an ISO 27001 certified vendor like Stacksync can significantly simplify your own audit process. You can provide our certificate to your auditors as evidence that a critical part of your supply chain meets international security standards. This can help reduce the scope of your audit and demonstrates due diligence in selecting secure partners, saving your team considerable time and effort.
How does Stacksync's product architecture support its ISO 27001 certification?
Our architecture is fundamental to our compliance. Instead of treating security as an add-on, we practice security by design. For example, our use of Configuration as Code (CaC) directly supports ISO 27001 controls for change management and secure configuration by ensuring every change is auditable, repeatable, and automated. This technical enforcement of our policies is a core reason we can maintain compliance continuously, not just at the time of an audit.