The standards we work to, the certifications behind our hosting, and how we keep pace with UK regulation.
| Do you hold ISO 27001, ISO 9001, or other relevant certifications? | Our practices align with ISO 27001 principles; formal ISO 27001 and ISO 9001 certification is held at our hosting layer by Microsoft Azure. We are a Microsoft Partner. ISO 27001 or Cyber Essentials Plus can be acquired for a specific engagement at additional cost. |
| Do you have processes to stay current with UK data protection and privacy regulations? | Yes Ongoing monitoring of ICO guidance and UK GDPR / DPA 2018 developments, with periodic policy review |
Assemblysoft is a focused specialist consultancy rather than a large enterprise vendor, and we are transparent about what that means for certification: we operate our information security practices in alignment with ISO/IEC 27001 principles — risk-based controls, least-privilege access, documented incident response, and continuity planning — as described across this Trust & Compliance Centre.
Formal certification is held where it matters most: at the infrastructure layer. Customer solutions are hosted on Microsoft Azure, which is independently certified against ISO/IEC 27001, ISO/IEC 27017/27018, ISO 9001, SOC 1/2/3, and Cyber Essentials Plus, among others. Microsoft's certificates and audit reports can be verified directly via the Microsoft Service Trust Portal and the Azure ISO 27001 compliance offering — see Hosting & Data Residency for the full set of links.
We are a Microsoft Partner, reflecting our depth in the Microsoft technology stack used to deliver customer solutions.
We partner with Vanta, the trust-management platform, for continuous, automated auditing and compliance monitoring. Our controls — across the cloud estate, access management, device security, and supplier posture — are checked continuously and the supporting evidence collected automatically, so our compliance position is maintained between reviews rather than reconstructed for them.
The same partnership works for our clients: we guide client platforms through SOC 2 Type II, ISO 27001, and GDPR certification with Vanta — preparing the technical baseline, leading the initial remediation sprint, and keeping the SDLC aligned so certification compounds across frameworks instead of duplicating effort. The full picture, including how certification unlocks enterprise and regulated-sector deals, is in the Vanta Compliance Partnership section of our Client Playbook.
Where a project or framework requires formal certification at our level rather than the hosting layer, ISO 27001 can be acquired at organisational level for a specific engagement, and Cyber Essentials Plus can be obtained on the same basis — in each case scoped to the engagement and agreed as part of the commercial arrangement at additional cost.
This is more practical for us than for most suppliers: we operate fully remotely over secure VPN, and our estate and development environments are entirely cloud-based and protected — no on-premise servers, no office network holding customer data. That keeps the certifiable scope small, well-defined, and quick to evidence.
We maintain an ongoing process to stay current with UK data protection and privacy regulation, covering:
Findings feed into a periodic review of our policies — privacy, security, and this compliance documentation — with each page showing its last review date.
If your due-diligence process requires specific certification evidence or completion of a security questionnaire, contact hello@assemblysoft.com — we respond to supplier questionnaires as part of onboarding.