> For the complete documentation index, see [llms.txt](https://trust.memori.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://trust.memori.ai/en/certifications/certifications-overview/iso-certifications/iso-27017-2021-certificate.md).

# ISO 27017:2021 Certificate

The certification that defines the specific security responsibilities for the cloud environments where AIsuru customer data resides.

### What it is

ISO/IEC 27017:2021 is an extension of ISO 27001 that provides additional security controls specific to cloud services. It addresses the typical issues of multi-tenant environments, shared responsibility management and the security of virtualized infrastructures.

### Why it is relevant for AIsuru

AIsuru is a platform delivered in SaaS, PaaS and On-Premise modes on multiple cloud infrastructures:

* **Cloudsome** – public cloud, Italy EU region: main hosting of the platform via CloudFoundry and Kubernetes
* **AWS (Amazon Web Services)** – Ireland EU region: S3 storage and GuardDuty; Germany EU region: MongoDB Atlas for MCP Gateway data
* **Hetzner** – Germany EU region: MCP Gateway hosting and management of its database

ISO 27017 governs how Memori manages security in these environments, clarifying the responsibilities between provider and customer.

### What it concretely guarantees

**Shared Responsibility Model** The standard precisely defines what is Memori's responsibility (secure configuration, access control, application monitoring) and what is the responsibility of the cloud provider (physical security of the data centers, network infrastructure).

**Specific cloud controls applied by Memori:**

* **Multi-tenant data segregation:** each business tenant sees only its own Agents, users and configurations. No customer's data is accessible to other customers
* **Cloud environment hardening:** secure configurations on AWS and Cloudsome, with firewalls, DMZ and IAM access control
* **Continuous monitoring:** AWS GuardDuty monitors the behavior of instances in real time and automatically detects anomalies (unauthorized access, potential malware)
* **Malware scanning of uploaded files:** every file uploaded by users as media or document is automatically scanned by GuardDuty before processing; infected files are blocked
* **Encryption in transit and at rest:** all communications take place via HTTPS/TLS; sensitive data is protected in accordance with the security policies documented in the management system
* **Blue-green deployment:** platform updates without service interruption, with the possibility of immediate rollback

**Cloud asset management:** All cloud assets (virtual servers, databases, S3 buckets, containers) are inventoried in the management system and subject to the security controls documented in the ISO procedure.

### How it differs from ISO 27001

While ISO 27001 establishes the general framework for security management, ISO 27017 adds cloud-specific controls that 27001 does not directly cover, such as:

* Secure decommissioning of cloud resources at the end of the contract
* Controls on virtual machines and containers
* Verification that cloud resources are properly configured and not left in an insecure default state

{% file src="/files/gOuvlbmzH5cnlVoc5UZs" %}
