Skip to main content

Compliance & Certifications

Independently verified, not self-asserted

Accredited third parties assess our controls every year against internationally recognized standards. Our certificates, audit reports and policies are published through Risk Ledger, where your assurance team can access them directly.

Evidence for your assurance team

Our certificates, audit reports, penetration test summaries and policies are published through Risk Ledger, alongside our completed responses to the standard security questionnaire. One profile, continuously maintained rather than assembled on request.

Connect with us there and your team gets access directly, without a separate document request cycle.

i2 Trust Center Hero (1)

Our certifications

Certifications are issued by accredited auditors and re-assessed annually. Scope statements are available on request.

ISO27001-1
ISO/IEC 27001:2022
CERTIFIED

Information security management system covering product development, hosting and support operations.

AICPA (1)
SOC 2 TYPE II
ANNUAL REPORT

Security, Availability and Confidentiality trust services criteria over a 12-month observation window.

Cyber Ess 3
CYBER ESSENTIALS
CERTIFIED

UK NCSC-backed scheme demonstrating baseline protection against common cyber threats.

Cyber Ess Plus 2
CYBER ESSENTIALS PLUS
IN PROGRESS

UK NCSC-backed scheme with hands-on technical verification of our technical controls.

ISO27701-1
ISO/IEC 27701
IN PROGRESS

Privacy information management extension to our ISMS.

ISO42001-1
ISO/IEC 42001
IN PROGRESS

Artificial intelligence management system standard supporting responsible AI governance.

GOV-UK2 (1)
UK PUBLIC SECTOR
LISTED

Listed supplier on UK public sector purchasing frameworks, with contract-specific assurance as required. 

CREST logo
CREST-TESTED
ANNUAL REPORT

Annual penetration testing performed by a CREST-accredited provider against product and infrastructure.

Frameworks we map to

Beyond certification, we maintain control mappings so customers can evidence their own obligations without a bespoke assessment.

Framework Relevance Our Position
UK GDPR / EU GDPR Processing of personal data Aligned; DPA with UK IDTA and EU SCCs
NIST Cybersecurity Framework US federal and commercial customers Control mapping available via Risk Ledger
NCSC Cloud Security Principles UK public sector procurement Documented assertion per principle
EU AI Act AI-enabled product capabilities Readiness assessment complete; see Responsible AI
NIS2 Directive Essential and important entities in the EU Supplier obligations supported contractually
DORA Financial services customers in the EU ICT third-party provisions available on request
Logo Arrows

Need more detailed assurance?

Procurement and assurance teams can access our full security documentation on Risk Ledger, including our SOC 2 report, ISO certificates and policies. If your review needs something we haven't published there, raise a support case and we'll confirm what we can provide.