ISO/IEC 27001 Compliance

Information Security Management System (ISMS) aligned with international standards

Our Commitment to Information Security

OptiCloud is designed and operated in alignment with ISO/IEC 27001:2022, the international standard for Information Security Management Systems (ISMS). This standard provides a systematic approach to managing sensitive company and customer information.

Our ISMS covers all aspects of the OptiCloud platform — from development and deployment to operations and incident response. We implement a risk-based approach to ensure that security controls are proportionate to the threats we face and the sensitivity of the data we process.

ISMS Scope

The OptiCloud Information Security Management System covers:

  • The OptiCloud multi-cloud cost and license management platform (SaaS, on-premises, and private cloud deployments)
  • All cloud provider integrations (Oracle Cloud, Microsoft Azure, Amazon AWS, Google Cloud Platform)
  • User authentication, authorization, and identity management via Keycloak
  • Data processing infrastructure hosted within the European Union
  • Development, testing, staging, and production environments

Security Controls (Annex A)

OptiCloud implements controls across all domains of ISO/IEC 27001 Annex A:

A.5 — Organizational Controls

Information security policies, defined roles and responsibilities, segregation of duties, and management oversight.

A.6 — People Controls

Background verification, security awareness training, disciplinary process, and responsibilities after termination.

A.7 — Physical Controls

EU-hosted data centers with physical access controls, equipment security, and environmental protection.

A.8 — Technological Controls

Endpoint security, privileged access management, secure authentication, and malware protection.

A.5.23 — Cloud Services

Cloud provider security assessment, SLA monitoring, and shared responsibility model for OCI/Azure/AWS/GCP.

A.8.24 — Cryptography

TLS 1.2+ for data in transit, AES-256 encryption at rest, and key management procedures.

A.8.15 — Logging

Centralized logging, tamper-proof audit trails with 7-year retention, and log monitoring.

A.8.25 — Secure Development

Secure SDLC, code review, SAST scanning, dependency vulnerability checks, and CI/CD pipeline security.

Access Control

OptiCloud enforces strict access control aligned with the principle of least privilege:

Role-Based Access (RBAC)

10 configurable roles from ReadOnly Viewer to SuperAdmin. Users see only data relevant to their role and organizational unit.

Single Sign-On (SSO)

Keycloak-based authentication with support for SAML, OIDC, and LDAP federation.

Multi-Factor Authentication

TOTP-based 2FA mandatory for privileged roles: SuperAdmin, CloudAdmin, SecurityOfficer.

Session Management

JWT tokens with 15-minute access token lifetime, 12-hour refresh tokens, and automatic session invalidation.

Cryptography & Data Protection

  • All data encrypted in transit using TLS 1.2+ with strong cipher suites
  • Data at rest encrypted with AES-256 in PostgreSQL and all backup storage
  • Cloud provider API keys stored in HashiCorp Vault with automatic rotation every 90 days
  • JWT tokens signed with RS256 algorithm, keys managed by Keycloak

Operations Security

  • Automated CI/CD pipeline with lint, unit tests (80%+ coverage), integration tests, SAST scan, and E2E tests before every deployment
  • Container images scanned for vulnerabilities before deployment to production
  • Infrastructure as Code (Docker Compose / Kubernetes) — all configuration versioned and auditable
  • Prometheus monitoring with 15-second scrape intervals, Grafana dashboards, and automated alerting
  • Change management process: all changes to production require pull request with 2 approvals

Incident Response

OptiCloud maintains a documented incident response plan aligned with ISO 27001 Annex A.5.24–A.5.28:

<1 hour

Incident detection, classification, and initial response team activation

<4 hours

Containment, impact assessment, and stakeholder notification

<72 hours

Root cause analysis, remediation, and GDPR breach notification if applicable

Audit & Monitoring

  • Complete audit trail for all user actions — who did what, when, and from where (requirement A.6)
  • 7-year audit log retention for regulatory compliance
  • Real-time security event monitoring via Prometheus and centralized logging
  • Annual internal security audits and periodic third-party penetration testing

Business Continuity

  • 99.9% uptime SLA with automated failover and health checks
  • PostgreSQL WAL-based point-in-time recovery with daily automated backups
  • Kafka message persistence ensures no data loss during service interruptions
  • Disaster recovery plan with documented RTO (4 hours) and RPO (1 hour) targets

Compliance & Continuous Improvement

Our ISMS follows the Plan-Do-Check-Act (PDCA) cycle for continuous improvement:

Internal Audits

Annual ISMS internal audits covering all Annex A controls

Management Review

Quarterly security reviews with risk register updates

Continuous Monitoring

Automated vulnerability scanning and dependency checks in CI/CD

Security Contact

For security-related inquiries, vulnerability reports, or to request our security documentation:

Last updated: March 2026