We build our software to a secure development lifecycle, test it independently, keep it current with modern security standards, and fix what we find. So the products you deploy stand up in the environments you run them in.
Most of our products don't run on our infrastructure. They run in your data centers, on your networks, and in environments that are often isolated from the public internet entirely.
That shapes everything about how we approach security. We can't patch around a problem after the fact, and we can't rely on controls we operate on your behalf. Security has to be built into the release itself, verified by assessors outside i2, and documented well enough that your teams can deploy and maintain it to your own standards in your environment, under your control.
Where we do host a service, the same discipline applies, backed by operational controls within our ISO 27001 scope.
Six disciplines, applied continuously and independently assessed each year.
Threat modelling at design, secure coding standards, automated security testing in every pipeline run and mandatory peer review before anything reaches a release.
Annual testing of our products by a CREST-accredited provider, with findings tracked to closure and a summary report published for customers.
Continuous scanning and dependency monitoring, with remediation targets tied to severity and security advisories issued directly to affected customers.
Every third-party component tracked, licence-reviewed and monitored for vulnerabilities, with a Software Bill of Materials published per release.
Hardened corporate and build environments with multi-factor authentication, endpoint detection, centralised monitoring and defined patching timescales.
Current TLS and cipher suite support, integration with your identity provider, and hardening guidance that keeps our products aligned with the controls you already run.
A plain-English summary of the controls behind our certifications. Full policy documents are available through our Risk Ledger profile.
If you've found a security issue in an i2 product, we want to hear about it.
From there it's triaged against the same severity model we apply to our own findings - a vulnerability reported from outside i2 moves through exactly the process one found by our engineers does.
Procurement and assurance teams can access our full security documentation on Risk Ledger, including our SOC 2 report, ISO certificates and policies. If your review needs something we haven't published there, raise a support case and we'll confirm what we can provide.
© 2026 i2 Group / N. Harris Computer Corporation. All trademarks owned by N. Harris Computer Corporation.
1 Cambridge Square, Milton Avenue, Cambridge, CB4 0AE, UK