> For the complete documentation index, see [llms.txt](https://trust.memori.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://trust.memori.ai/en/certifications/certifications-overview/iso-certifications/iso-27001-2022-certificate.md).

# ISO 27001:2022 Certificate

The certification that ensures customer information is protected by formal, verifiable systems.

### What it is

ISO/IEC 27001:2022 defines the requirements for implementing, monitoring, maintaining and continually improving an Information Security Management System (ISMS). It is the international reference standard for the protection of company information and customer data.

### What it concretely guarantees

The certification requires Memori to manage information security through a risk-based approach that is documented and subject to periodic audits. In particular:

* **Access control:** only authorized people access information, with differentiated permissions for reading, writing, modifying and deleting
* **Malware protection:** threat detection and prevention systems active on the cloud infrastructure and on files uploaded to the platform
* **Information backup:** backups stored on cloud infrastructure in Europe (EU)
* **Logging and monitoring:** logs of the activities of users and system administrators, with alerts for anomalous behavior
* **Technical vulnerability management:** continuous process of detection, analysis and correction of vulnerabilities, tracked in the management system
* **Secure development:** "security by design" principles applied to the entire lifecycle of the AIsuru software, from design to release

### How it applies to AIsuru

In the context of the AIsuru platform, ISO 27001 governs the protection of:

* Source code and configurations of cloud environments
* Conversation data of the end users of AI Agents
* Credentials and application secrets (API keys, access tokens for LLM providers)
* Configuration information of business tenants (PaaS)
* Application logs generated during service operation

The logical separation of environments (development → staging → production) and the automated CI/CD pipelines on Bitbucket ensure that no code change reaches production without going through documented review and testing processes.

### Audit and maintenance

The certification is subject to periodic audits by an accredited third-party body. Memori maintains the certification through:

* Periodic management reviews
* Documented management of nonconformities and corrective actions
* Continuous updating of the risk assessment
* Staff training and awareness

{% file src="/files/PCrfiZRMDjzQjDBNKbo9" %}
