In preparation, and honest about it.
We are working toward ISO/IEC 27001 certification. It is not yet held, and nothing on this page claims it. What you can do today: assess the shipped controls yourself, and file a standing request so the certificate reaches you the day it exists.
The certification track, station by station.
-
01 · Done
Scoping & gap analysis
The ISMS scope is drawn around how the product is built, released and operated; the gap list is the work plan.
-
02 · Done
Controls & evidence
Annex A controls implemented and generating evidence, most live in the product and pipeline, documented below.
-
03 · In progress
Internal audit
The ISMS is being audited against its own scope before anyone external looks; findings feed back into the controls.
-
04 · Then
Certification audit
An accredited body examines the ISMS; the certificate lands on this page, and with everyone whose request is standing.
No promised dates, a date named before the internal audit closes would be theatre. The state of the work is shareable at any time from your account.
The control themes, as shipped mechanisms.
Group permissions enforced inside every query; invitation-only accounts; write-only credentials; per-IP backoff and lockout on every sign-in surface
TLS in transit; secrets sealed server-side; releases, heartbeats and leases signed (Ed25519); webhook signatures verified per platform
Single-tenant deployments, one database per client; hash-chained tamper-evident audit log; safety backup before every update, automatic rollback on failed health checks
Release gate on every build, static checks, the full test suite, signed artifacts; one failed gate blocks the release for the whole fleet
At most two sub-processor categories, none at all when self-hosting with self-hosted AI; the Naxis AI service runs under DPA with zero-retention terms
Signed heartbeats with disturbance events; short-lived leases let a compromised instance be stopped remotely; support access to client instances is consent-gated per ticket
Each theme is documented in the trust library, readable now, no certificate required to verify a mechanism exists.
What to request, today and the day it lands.
The certificate is not yet held and is not claimed anywhere on this site; the ISO 27001 page shows exactly where the track stands. A standing request is fulfilled the day the certificate exists, and the current state is shareable on your thread meanwhile.
An account action, the request files under your Naxis account, and the answer arrives on its thread.
How a deployment is built: the single-tenant boundary, the permission model, the audit chain and the AI data flow: the document a security review starts with.
An account action, the request files under your Naxis account, and the answer arrives on its thread.
Send your own questionnaire: CAIQ, SIG, or your in-house sheet, in the request note. Answers come from the architecture, not a boilerplate script.
An account action, the request files under your Naxis account, and the answer arrives on its thread.
ISO 27001 status, answered
Is Naxis ISO 27001 certified?
Not yet. We are working toward ISO/IEC 27001 certification and say so plainly, no certificate is claimed anywhere on this site until one is held. The control themes the standard expects are shipped, assessable mechanisms today.
Can we deploy before you are certified?
Many organisations do exactly that: assess the controls directly, the architecture overview, the trust library, your own questionnaire answered from the architecture, sign the DPA, and file a standing request so the certificate reaches you the day it exists.
Can we see where the preparation actually stands?
Yes. Request it from your account and you get the current preparation state on your own thread, which track stage is in progress, what evidence exists, what remains. No glossy roadmap, the real state.
Who will the certification body be?
An accredited certification body, named on this page when the audit is engaged. We do not pre-announce a name we have not contracted.
Does self-hosting change the certification scope?
The ISMS covers how we build, release and operate the product and the managed fleet. A self-hosted deployment runs the same signed artifact on your infrastructure, your own physical and network controls apply there, and the product controls travel with it.
Assess the controls yourself.
The mechanisms are shipped and documented, a certificate will confirm them, not create them.