Skip to content

Glossary

What is ISO 27001?

ISO 27001 is the international standard for information security management, certifying that an organisation runs a systematic, audited process for identifying and controlling security risks.

ISO 27001 is the leading global standard for an information security management system (ISMS). Rather than prescribing a fixed checklist of tools, it requires an organisation to run a continuous process: identify its information risks, apply appropriate controls, and review and improve them over time. Certification means an accredited body has audited that the process genuinely exists and works.

It pairs with a control catalogue, commonly the ISO 27002 guidance, covering areas such as access control, cryptography, physical security, supplier management and incident response. The certificate itself attests to the management system; the controls are how that system is put into practice.

Like SOC 2, ISO 27001 certifies an organisation, not an app. When a product cites ISO 27001, the useful question is whose certificate it is - the product operator's, or its infrastructure providers'.

In 99 Data Rooms

How it works here.

99 Data Rooms runs on ISO 27001 certified infrastructure - its providers Supabase and Cloudflare hold those certifications. 99 Data Rooms does not itself claim an ISO 27001 certificate; it belongs to the underlying platforms. Documents are UK-hosted in London and encrypted at rest, gated per viewer, with a Data Processing Agreement available on request.

Common questions

ISO 27001, in short.

Is 99 Data Rooms ISO 27001 certified?

The ISO 27001 certifications are held by its infrastructure providers, Supabase and Cloudflare. 99 Data Rooms builds on that certified infrastructure and does not claim its own certificate. The security page lists the provider certifications.

What is the difference between ISO 27001 and SOC 2?

Both are recognised information-security assurances audited by a third party. ISO 27001 is an international certification of a security management system; SOC 2 is a US attestation report against trust criteria. Many providers hold both.

Related terms

Try it on a real document. Turn a PDF into a tracked, revocable link in a couple of minutes. Three rooms stay free for as long as you want them, no card required.