ISO 27001

International standard for Information Security Management Systems (ISMS). A systematic approach to managing sensitive company and customer information.

What is ISO 27001?

ISO/IEC 27001 is the world's best-known standard for information security management systems (ISMS). It provides a framework for organizations to establish, implement, maintain, and continually improve their information security practices.

For quiXzoom, ISO 27001 certification demonstrates our commitment to protecting the confidentiality, integrity, and availability of all data entrusted to us — from Zoomer personal information to enterprise client mission data.

Scope of Certification

The quiXzoom ISMS covers the following scope:

  • Organizational Units: quiXzoom Inc. (US) and Landvex AB (Sweden)
  • Systems: quiXzoom mobile app (iOS/Android), web platform, API infrastructure, and data processing pipelines
  • Locations: Remote workforce with cloud infrastructure hosted in AWS EU regions
  • Data Types: Personal data, observation data (photos, GPS), payment data, and enterprise client data

Annex A Controls in Scope

ISO 27001:2022 includes 93 controls organized into 4 themes. The following control sets are in scope for quiXzoom:

A.5 — Organizational Controls

Policies, roles, risk assessment, and supplier relationships

A.6 — People Controls

Screening, terms of employment, awareness training

A.7 — Physical Controls

Physical security perimeters, equipment security, storage media

A.8 — Technological Controls

Encryption, access control, vulnerability management, logging

Key ISMS Processes

  • Risk Assessment: Annual formal risk assessment with quarterly reviews
  • Incident Management: 24/7 incident response with 48-hour notification SLA
  • Access Control: Role-based access with quarterly reviews and MFA enforcement
  • Asset Management: Inventory of all information assets with ownership and classification
  • Business Continuity: Disaster recovery plans tested semi-annually
  • Supplier Management: Security assessments for all critical third-party vendors
  • Internal Audit: Annual internal audit program with independent audit trail
  • Management Review: Quarterly ISMS review by senior leadership

Certification Timeline

Q1 2026

ISMS Implementation

Established information security policies, procedures, and risk treatment plan.

Q2 2026

Internal Audit

First internal audit completed. Non-conformities addressed and closed.

Q4 2026

Stage 1 & 2 Audit

External certification body conducts documentation review and on-site audit.

Q1 2027

Certificate Issued

ISO 27001:2022 certificate awarded. Surveillance audits annually thereafter.

Request the Certificate

Once issued, a summary of our ISO 27001 certificate (including certification body, scope, and validity dates) will be published on this page. Enterprise customers may request the full certificate under NDA by contacting security@quixzoom.com.