Certifications & attestations

We would rather tell you exactly where we are than imply more than is true. Here is our honest status on the two frameworks enterprise buyers ask about most, plus the dates we are working toward.

SOC 2 Type IIIn audit
ISO/IEC 27001In progress
NDPRCompliant
CBN alignedCompliant
In audit

SOC 2 Type II

An independent auditor evaluates our controls against the Trust Services Criteria, security, availability and confidentiality, over an observation period.

Scope

The Qoyla platform, supporting infrastructure and the processes that operate them.

Status

Type I controls designed and in place. Type II observation window underway, report expected Q4 2026.

In progress

ISO/IEC 27001

The international standard for an information security management system, certified by an accredited body after a two-stage external audit.

Scope

Our ISMS covering the design, development and operation of Qoyla.

Status

ISMS established and internal audits running. Stage 1 audit scheduled, certification targeted for H1 2027.

The path

Our compliance roadmap.

Done

NDPR compliance & DPO appointed. Lawful basis mapped, records of processing maintained.

Done

Independent penetration test. First external assessment completed, findings remediated.

Now

SOC 2 Type II observation window. Controls operating and being evidenced over time.

Q4 2026

SOC 2 Type II report issued. Available to customers and prospects under NDA.

H1 2027

ISO/IEC 27001 certification. Stage 1 and 2 audits, then certificate issued.

Need the documents?

Request reports & evidence

Audit reports, penetration-test summaries and our security whitepaper are available to customers and qualified prospects under NDA. Tell us what you need and we will send it as soon as it is ready.

SOC 2 report · on issue, under NDA
Penetration-test summary · latest available
Security whitepaper · available now

Request access

We respond within one business day.