HomeTrust & Security › ISO 27001 Certification
ISO/IEC 27001:2022 · CERTIFIED

Certified under ISO/IEC 27001:2022

Headx Monitor holds ISO/IEC 27001:2022 certification for its information security management system, covering both Cloud and On-Premise deployments.

ISO/IEC 27001:2022 Certified Cloud + On-Premise in scope Annual surveillance audits
Last updated August 15, 2026 IST · Document version 2.0 · Reviewed quarterly
ISO/IEC 27001 : 2022 CERTIFIED SOC 2 TYPE I CERTIFIED
Certification
ISO/IEC 27001:2022
Information security management
ISMS scope
Cloud + On-Prem
Both deployments in scope
Annex A controls
Implemented
SoA available under NDA
Risk treatment
Operating
Register reviewed quarterly
Auditor
Accredited body
Stage 1 & 2 passed
Maintenance
Annual surveillance
3-year certification cycle
Headx Monitor is certified under ISO/IEC 27001:2022. The certificate and the Statement of Applicability (Annex A control-by-control with implementation evidence) are available from sales on request — the certificate directly, the SoA under NDA.

1 Certification summary

StandardISO/IEC 27001:2022 (Information security, cybersecurity and privacy protection — Information security management systems — Requirements)
Status Certified
ScopeThe information security management system supporting the Headx Monitor platform — Cloud (SaaS, AWS ap-south-1) and On-Premise delivery.
CertificateAvailable from sales on request
Certification cycleThree-year cycle with annual surveillance audits by an accredited certification body

2 Controls implemented

All Annex A controls applicable to Headx Monitor's scope are implemented and operating across the four control themes:

Organisational controls (Clause 5)

  • Information security policy approved and reviewed annually
  • Roles and responsibilities defined (CISO, DPO, security operations)
  • Segregation of duties between development and production access
  • Contact with authorities (CERT-In, sector regulators)
  • Threat intelligence subscription and integration
  • Information security in project management — security-review gate on every release
  • Information transfer policies (with sub-processors, with customers)
  • Access control policy with RBAC + named privilege escalation

People controls (Clause 6)

  • Background verification for all employees
  • Terms and conditions of employment include confidentiality obligations
  • Disciplinary process for information security violations
  • Information security awareness training — onboarding + annual refresh
  • Remote working security policy
  • Reporting of information security events workflow

Physical controls (Clause 7)

  • Physical security perimeters at office locations
  • Physical entry controls (access cards, visitor management)
  • Security of offices, rooms, facilities
  • Secure disposal or reuse of equipment
  • Equipment maintenance and decommissioning procedures
  • Production infrastructure AWS-hosted; AWS ap-south-1 physical controls inherited via the Shared Responsibility model

Technological controls (Clause 8)

  • User access provisioning, review, and revocation
  • Privileged access management (just-in-time, time-boxed)
  • Information access restriction (need-to-know + RBAC)
  • Secure authentication (bcrypt, lockouts, session timeouts)
  • Capacity management with auto-scaling
  • Protection against malware (EDR on all endpoints)
  • Backup and recovery — daily full, hourly incremental, cross-AZ replication
  • Logging and monitoring — centralised, SIEM-ready, anomaly detection
  • Networks security (Cloudflare WAF, private subnets, egress controls)
  • Cryptography — TLS 1.3, AES-256, KMS key management, quarterly key rotation
  • Secure development life cycle
  • Application security testing — SAST, SCA, DAST, annual external pen test
  • Test data management — production data is never used in development or test
  • Change management — approval workflow, rollback procedures
  • Vulnerability management — daily SCA, monthly scans, CVE-based patch SLAs

The full Statement of Applicability (Annex A control-by-control with implementation evidence) is available under NDA.

3 Surveillance & recertification

ISO/IEC 27001 certification is maintained on a three-year cycle. The certification body conducts annual surveillance audits to confirm the ISMS continues to operate effectively, with a full recertification audit at the end of each cycle.

ActivityFrequency
Internal ISMS auditAnnual (full scope)
Management reviewQuarterly
External surveillance auditAnnual
Recertification auditEvery three years

4 Documents available

The certificate is available directly; the following supporting artefacts are available under signed NDA, typically within 24 hours of request:

  • ISO/IEC 27001:2022 certificate — available on request
  • Statement of Applicability (SoA) — control-by-control applicability and implementation evidence
  • ISMS scope statement — what is in / out of certification scope
  • Information security policy — board-approved, current version
  • Risk assessment and treatment plan — current risk register
  • Internal audit report — latest internal audit findings and closure status
  • Management review minutes — quarterly
  • Penetration test executive summary — latest annual external test
  • Sub-processor register with annual review records

Request via info@headx.in.

5 Other certifications

StandardStatusNotes
ISO/IEC 27001:2022 CertifiedThis page
SOC 2 Type I CertifiedTrust services criteria; report available on request
GDPR DPA template availableAvailable now
HIPAA BAA available on requestHealthcare-adjacent customers
DPDP Act 2023 (India) AlignedSee DPDP status
PCI DSSOut of scopePayment flows handled by Cashfree / Razorpay

6 Contact

Related documents

Need detailed audit evidence or a signed DPA?

The full Statement of Applicability, latest penetration-test summary, sub-processor register with annual review records, and pre-filled CAIQ / SIG questionnaires are available under NDA — typically within 24 hours (IST business days).