AegisOne

Trust

ISO/IEC 27001 compliant. Built so you can evidence it too.

AegisOne’s information security management controls are implemented in line with ISO/IEC 27001, and the platform is built to produce the evidence your own programme runs on — access records, asset inventory, patch position, audit trails and control scoring, continuously rather than in the fortnight before an assessment.

What AegisOne brings to your compliance programme

  • Controls implemented to the standard. Access control, asset inventory, audit logging, vulnerability management and patch governance are implemented in line with ISO/IEC 27001, so the platform fits the control set your assessor already works from.
  • Evidence produced continuously. Control posture is scored from what your endpoints actually report, and every score opens onto the findings behind it. Evidence packages export on demand rather than being assembled by hand before an audit.
  • Your certification stays yours. Certification is awarded to an organisation — its policies, its people, its assessment. AegisOne carries the technical weight of that programme and produces the artefacts, so what your assessor asks for is already waiting.

§20.1 — The difference that matters

Certified, aligned, designed to support, in progress

These four words get used interchangeably across this industry, and the distinction between them is precisely the thing a buyer needs. Every framework below carries exactly one of them, and the wording is generated from a registry — not written per page.

Certified

Certified

An accredited certification body has issued a valid certificate covering the stated entity and scope.

What you can conclude
Rely on an independent accredited body having examined the stated scope and issued a certificate you can validate yourself.
Good to know
Assume the certificate covers services or entities outside the scope printed on it.

Compliant

Compliant

AegisOne’s controls are implemented in line with this standard. This is our own attestation of control implementation, distinct from a certificate issued by an accredited body.

What you can conclude
Expect our controls to be implemented in line with the standard, and ask us how any individual control is implemented.
Good to know
Treat this as a certificate issued by an accredited body — that is the separate “Certified” level above.

Aligned

Aligned

AegisOne’s own controls are designed against this standard’s principles. This is not a certification.

What you can conclude
Expect our internal controls to have been designed against the standard’s principles, and ask us how a given control is implemented.
Good to know
Treat this as a certification, present it to an auditor as one, or infer that any third party has verified it.

Designed to support

Designed to support

AegisOne provides capabilities and evidence that help your organisation meet this framework. It does not make your organisation compliant.

What you can conclude
Use AegisOne to implement technical controls and produce the evidence your own assessment requires.
Good to know
Conclude that deploying AegisOne makes your organisation compliant with the framework.

Certification in progress

Certification in progress

Formal work toward certification is underway. No certificate has been issued yet.

What you can conclude
Know that formal certification work has started, and ask us where it stands.
Good to know
Rely on it. No certificate has been issued.

Every certification claim on this site is published with its full certificate record — issuing body, certificate number, legal entity, scope, issue and expiry dates, and an independent validation route — so you can verify it yourself rather than take our word for it. That completeness is enforced automatically at build time.

Frameworks

Every claim we make, with its level attached

Each statement below is the exact wording we are permitted to use for that framework. We have not paraphrased it here, and we do not paraphrase it in sales conversations either.

ISO/IEC 27001

Compliant

AegisOne is ISO/IEC 27001 compliant. Our information security management controls are implemented in line with the standard, covering access control, asset management, operations security, audit logging and vulnerability management.

Compliant: AegisOne’s controls are implemented in line with this standard. This is our own attestation of control implementation, distinct from a certificate issued by an accredited body.

How AegisOne helps

  • Access control evidence through role-based operator accounts and MFA
  • Asset inventory covering hardware and software across the estate
  • Audit logging of privileged actions
  • Vulnerability and risk registers

Where a certificate exists, we publish its number, scope and an independent verification route on this card so you can check it yourself.

SOC 2

Designed to support

AegisOne helps organisations implement and evidence controls that support their SOC 2 objectives.

Designed to support: AegisOne provides capabilities and evidence that help your organisation meet this framework. It does not make your organisation compliant.

How AegisOne helps

  • Continuous endpoint monitoring evidence
  • Change and action audit trails
  • Access review support through operator and login records
  • Exportable evidence packages

Where a certificate exists, we publish its number, scope and an independent verification route on this card so you can check it yourself.

HIPAA

Designed to support

AegisOne provides technical controls and evidence that support a covered entity’s HIPAA Security Rule programme. Use of AegisOne does not by itself make an organisation HIPAA compliant.

Designed to support: AegisOne provides capabilities and evidence that help your organisation meet this framework. It does not make your organisation compliant.

How AegisOne helps

  • Workstation inventory and health monitoring
  • Audit controls over administrative access
  • Patch position reporting across clinical endpoints
  • Credential handling with audited reveal

Where a certificate exists, we publish its number, scope and an independent verification route on this card so you can check it yourself.

PCI DSS

Designed to support

AegisOne supports controls associated with PCI DSS requirements for asset inventory, patching and access management.

Designed to support: AegisOne provides capabilities and evidence that help your organisation meet this framework. It does not make your organisation compliant.

How AegisOne helps

  • Maintained inventory of in-scope endpoints
  • Patch position and remediation evidence
  • Vulnerability register
  • Multi-factor authentication for administrative access

Where a certificate exists, we publish its number, scope and an independent verification route on this card so you can check it yourself.

GDPR

Designed to support

AegisOne is built to support customers’ obligations as data controllers, with documented processing, retention controls and subprocessor transparency.

Designed to support: AegisOne provides capabilities and evidence that help your organisation meet this framework. It does not make your organisation compliant.

How AegisOne helps

  • Documented data processing and retention settings
  • Subprocessor list available on request
  • Access controls over personal data held in the platform

Where a certificate exists, we publish its number, scope and an independent verification route on this card so you can check it yourself.

NIST Cybersecurity Framework

Designed to support

AegisOne capabilities map to Identify, Protect, Detect and Respond functions of the NIST Cybersecurity Framework.

Designed to support: AegisOne provides capabilities and evidence that help your organisation meet this framework. It does not make your organisation compliant.

How AegisOne helps

  • Identify — asset and software inventory
  • Protect — patch management and endpoint hardening evidence
  • Detect — endpoint health and vulnerability visibility
  • Respond — remediation rules and incident records

Where a certificate exists, we publish its number, scope and an independent verification route on this card so you can check it yourself.

CIS Controls

Designed to support

AegisOne supports implementation of foundational CIS Controls, particularly inventory, vulnerability management and controlled administrative access.

Designed to support: AegisOne provides capabilities and evidence that help your organisation meet this framework. It does not make your organisation compliant.

How AegisOne helps

  • CIS Control 1 & 2 — hardware and software inventory
  • CIS Control 7 — continuous vulnerability management
  • CIS Control 5 & 6 — account and access control management

Where a certificate exists, we publish its number, scope and an independent verification route on this card so you can check it yourself.

No seal, badge image or accreditation mark is rendered for any framework on this page. Framework names appear as text only, to identify the standard being discussed — not to imply endorsement, membership or approval by the body that maintains it.

§20.4 — Division of responsibility

What we do, and what remains yours

The clearer this split is, the faster your assessment goes. AegisOne carries the technical evidence; your organisation holds the policy, the scope and the sign-off.

AegisOne provides

  • Hardware and software inventory across the endpoints you manage
  • Patch position and remediation records per endpoint
  • A vulnerability, findings, incident and risk register
  • Control-framework scoring with a findings list
  • Append-only audit records of privileged operator actions
  • Exportable evidence packages and executive reporting

You remain responsible for

  • Defining the scope of your compliance programme
  • Writing, approving and maintaining your policies
  • Risk assessment, treatment decisions and management review
  • Staff awareness, training and vetting
  • Engaging an accredited body and passing your own audit
  • Deciding whether the evidence AegisOne produces satisfies your assessor

As with any platform in this category, certification is awarded to your organisation rather than to the software it runs. AegisOne is built to carry the technical half of that programme and to make the evidence easy to produce.

In the product

The evidence layer is a shipped feature

Compliance work fails at evidence-gathering far more often than at control design. AegisOne treats the export as the deliverable: scoring against frameworks, a findings register, on-demand scans and a package you can hand to an assessor.

Compliance Frameworks & Evidence

Score endpoints against control frameworks and export the evidence auditors request.

  • Multiple control frameworks with per-client scoring
  • Compliance findings register
  • On-demand compliance scan per endpoint
  • Evidence collection and export

MFA & Audit Logging

Multi-factor authentication for operators and a durable audit trail.

  • TOTP multi-factor setup, verification and disable
  • Login attempt tracking
  • Audit log across privileged actions
  • Invite-based operator onboarding
AegisOne · Compliance evidenceIllustration

Framework coverage

  • ISO/IEC 2700184%
  • CIS Controls91%
  • NIST CSF78%

Control coverage scored from endpoint state. This supports your compliance programme; it is not an assessment or a certification.

Open findings

  • A.8.7Endpoint protection not reportingHigh
  • A.8.8Critical patches outstandingHigh
  • A.5.15Dormant privileged accountMedium
  • A.8.9Configuration drift on 6 devicesLow

Scoring is computed from endpoint state, and findings are raised against the control they touch. That is a working input to your assessment — it is not an assessment, and no score shown anywhere in the product constitutes a certification.

Documentation

What we can send your assessment team

Provided on request so you receive the current, dated version rather than a cached file.

  • Security overview
  • Architecture overview
  • Data-flow summary
  • Subprocessor list
  • Data Processing Agreement
  • Vulnerability disclosure policy
  • Incident response overview
  • Data retention and deletion summary

Our standard Data Processing Agreement and subprocessor list are published as drafts pending legal review. Treat the versions we send you on request as authoritative.