ISO 27001
International standard for Information Security Management Systems (ISMS). A systematic approach to managing sensitive company and customer information.
What is ISO 27001?
ISO/IEC 27001 is the world's best-known standard for information security management systems (ISMS). It provides a framework for organizations to establish, implement, maintain, and continually improve their information security practices.
For quiXzoom, ISO 27001 certification demonstrates our commitment to protecting the confidentiality, integrity, and availability of all data entrusted to us — from Zoomer personal information to enterprise client mission data.
Scope of Certification
The quiXzoom ISMS covers the following scope:
- Organizational Units: quiXzoom Inc. (US) and Landvex AB (Sweden)
- Systems: quiXzoom mobile app (iOS/Android), web platform, API infrastructure, and data processing pipelines
- Locations: Remote workforce with cloud infrastructure hosted in AWS EU regions
- Data Types: Personal data, observation data (photos, GPS), payment data, and enterprise client data
Annex A Controls in Scope
ISO 27001:2022 includes 93 controls organized into 4 themes. The following control sets are in scope for quiXzoom:
A.5 — Organizational Controls
Policies, roles, risk assessment, and supplier relationships
A.6 — People Controls
Screening, terms of employment, awareness training
A.7 — Physical Controls
Physical security perimeters, equipment security, storage media
A.8 — Technological Controls
Encryption, access control, vulnerability management, logging
Key ISMS Processes
- Risk Assessment: Annual formal risk assessment with quarterly reviews
- Incident Management: 24/7 incident response with 48-hour notification SLA
- Access Control: Role-based access with quarterly reviews and MFA enforcement
- Asset Management: Inventory of all information assets with ownership and classification
- Business Continuity: Disaster recovery plans tested semi-annually
- Supplier Management: Security assessments for all critical third-party vendors
- Internal Audit: Annual internal audit program with independent audit trail
- Management Review: Quarterly ISMS review by senior leadership
Certification Timeline
Q1 2026
ISMS Implementation
Established information security policies, procedures, and risk treatment plan.
Q2 2026
Internal Audit
First internal audit completed. Non-conformities addressed and closed.
Q4 2026
Stage 1 & 2 Audit
External certification body conducts documentation review and on-site audit.
Q1 2027
Certificate Issued
ISO 27001:2022 certificate awarded. Surveillance audits annually thereafter.
Request the Certificate
Once issued, a summary of our ISO 27001 certificate (including certification body, scope, and validity dates) will be published on this page. Enterprise customers may request the full certificate under NDA by contacting security@quixzoom.com.