We would rather tell you exactly where we are than imply more than is true. Here is our honest status on the two frameworks enterprise buyers ask about most, plus the dates we are working toward.
An independent auditor evaluates our controls against the Trust Services Criteria, security, availability and confidentiality, over an observation period.
The Qoyla platform, supporting infrastructure and the processes that operate them.
Type I controls designed and in place. Type II observation window underway, report expected Q4 2026.
The international standard for an information security management system, certified by an accredited body after a two-stage external audit.
Our ISMS covering the design, development and operation of Qoyla.
ISMS established and internal audits running. Stage 1 audit scheduled, certification targeted for H1 2027.
The path
NDPR compliance & DPO appointed. Lawful basis mapped, records of processing maintained.
Independent penetration test. First external assessment completed, findings remediated.
SOC 2 Type II observation window. Controls operating and being evidenced over time.
SOC 2 Type II report issued. Available to customers and prospects under NDA.
ISO/IEC 27001 certification. Stage 1 and 2 audits, then certificate issued.
Need the documents?
Audit reports, penetration-test summaries and our security whitepaper are available to customers and qualified prospects under NDA. Tell us what you need and we will send it as soon as it is ready.