We are not certified yet. Check us anyway.
AONE does not hold ISO/IEC 27001 today — we are implementing it, and we will not describe ourselves as certified until a certificate exists with a number we can print. What follows is everything you would examine if we did hold it: the layers, the lifecycle, the controls, and the evidence we can put in front of your assessor for each one.
Status, stated without spin.
Held means a certificate exists. In progress means it does not. Aligned means we design and build to the standard but claim no third-party attestation.
ISO/IEC 27001 — Information security management
Our information security management system is being implemented against the standard. We are not certified, and we will not describe ourselves as certified until a certificate is issued and its number appears in this row.
ISO 9001 — Quality management
Quality management processes are being documented against the standard ahead of assessment. Not certified today.
OWASP ASVS & Top 10
Application controls are designed against the OWASP Application Security Verification Standard, and the Top 10 categories form part of our code review checklist.
CERT-In directions — incident reporting & log retention
Incident handling is built to the six-hour reporting window, and systems retain logs for the required 180-day period within Indian jurisdiction.
Digital Personal Data Protection Act, 2023
Personal data handling, purpose limitation, retention and data-principal request routes are designed to the Act. A named contact handles requests.
GIGW — Government website guidelines
Public-facing government surfaces are built to the Guidelines for Indian Government Websites, including accessibility and multilingual requirements.
Independent VAPT
Vulnerability assessment and penetration testing is performed by an independent party rather than by us. Where procurement requires a CERT-In empanelled auditor, we engage one.
If certification is a hard gate in your procurement, say so at the first conversation. We would rather tell you the timing does not work than waste a bid cycle for both of us.
Seven layers, and the question each one gets asked
Controls in the pipeline, not in a policy document
Who can reach your data, at which point
Every control, and the evidence behind it.
This is the page's actual argument. A certificate says a third party saw evidence once. This names the artefact we will put in front of your assessor, control by control.
| Area | Control | Evidence we can produce |
|---|---|---|
| Access | Every account is attributable to a named individual; no shared credentials exist. | Account inventory with owner, role and last review date. |
| Access | Production access is time-bound and requires approval from a second person. | Elevation request log showing requester, approver, scope and expiry. |
| Access | Leavers are de-provisioned across all systems as part of exit. | Offboarding checklist with per-system sign-off. |
| Data | Data residency and retention are agreed in writing before build begins. | Signed data-handling schedule attached to the engagement contract. |
| Data | No production data is copied into development or staging environments. | Environment configuration and seeded-data generation scripts. |
| Data | Deletion is verified rather than assumed, and can be certified on request. | Deletion procedure and completion record per data set. |
| Application | Dependency and secret scanning block the merge; they do not raise a ticket. | Pipeline configuration and a sample of blocked builds. |
| Application | Security review by a person is a required gate before any production release. | Release records showing reviewer and date for each deployment. |
| Infrastructure | Infrastructure is defined as code; console changes are exceptions that get reviewed. | Repository history and drift-detection output. |
| Infrastructure | Secrets live in managed key stores, never in source control. | Key store inventory and repository scan history. |
| Monitoring | Privileged and record-affecting actions are logged immutably and retained to policy. | Log schema, retention configuration and a worked query. |
| Response | Incidents follow a defined severity model with agreed response targets. | Incident runbook, on-call roster and past post-mortems where disclosable. |
Nobody believes “it won’t break”.
They believe a firm that has published its severity model, its response targets and what it does in the first hour. These are our standard targets; a contract may set tighter ones.
| Definition | Response | Updates | |
|---|---|---|---|
| S1Critical | System unavailable, data at risk, or a security incident in progress. Includes any suspected breach of personal data. | 30 minutes | Hourly, until resolved |
| S2Major | Core function unavailable or materially degraded for a significant share of users, with no workaround. | 2 hours | Every 4 hours |
| S3Minor | A function is impaired, but a workaround exists and normal operation continues. | 1 working day | Daily |
| S4Low | Cosmetic or non-urgent, scheduled into the normal delivery cycle. | 3 working days | On change |
- A suspected security incident is treated as S1 until proven otherwise, not after it is confirmed.
- Reportable incidents are notified to CERT-In within the six-hour window their directions require.
- Affected clients are told what we know, when we know it — including while the picture is still incomplete.
- Every S1 produces a written post-mortem covering cause, timeline, impact and the change that prevents recurrence.
- Post-mortems are blameless in tone and specific in content. A vague one is not accepted internally.
Send us your vendor assessment
We keep our answers current between engagements rather than assembling them per request, so a completed questionnaire comes back with the proposal instead of three weeks later. Send it with your first enquiry.
The awkward ones, answered first.
- Are you ISO 27001 certified?
- No. We are implementing an information security management system against the standard and intend to certify, but we do not hold the certificate today and will not imply otherwise. Everything on this page describes controls that are in place now, and we will evidence any of them on request. If certification is a hard gate in your procurement, tell us early and we will tell you honestly whether the timing works.
- Then why should we trust your security posture?
- Because you can check it. The controls register on this page names the evidence we can produce for each control — access logs, pipeline configuration, elevation records, retention schedules. A certificate is a third party asserting that such evidence existed on the day they looked. We are offering to show you the evidence directly.
- Can you complete our vendor security questionnaire?
- Yes, and quickly. We keep answers current between engagements rather than assembling them per request. Send it with your first enquiry and it comes back with the proposal, not three weeks later.
- Who can access our production data?
- By default, nobody. Production access is time-bound, requires approval from a second person, and every elevation is logged with requester, approver, scope and expiry. Where an engagement requires standing access for named individuals, they are named in the contract.
- Where is our data stored?
- Wherever the engagement requires, stated in writing before build begins and honoured in the deployment topology. For legislative and government data that means Indian jurisdiction. We are equally happy to deploy into your own cloud tenancy so the data never sits in an account we control.
- Do you carry out penetration testing?
- We coordinate it rather than perform it on our own work — marking your own homework is not assurance. Where your procurement requires a CERT-In empanelled auditor, we engage one and share the report and remediation record with you.
- What happens if you are breached?
- A suspected incident is treated as critical from the first minute rather than after confirmation. You are told what we know while we still know very little, CERT-In is notified inside the six-hour window, and a written post-mortem follows covering cause, timeline, impact and the specific change that prevents recurrence.
Let’s build what’s next.
Tell us where your business wants to grow. In one conversation we will show you where AI and software will pay back first, and whether we are the right team to build it.
- 30 minutes, free, no obligation
- A clear, practical recommendation
- Your ideas and data kept confidential
Book a free strategy call
We look at your goals, your current systems and your biggest time and cost drains, then recommend the first AI or software move with the fastest payback.
Book my strategy callRequest a briefing
A working session on your requirement, our reference deployments and a capability statement.
Public sector