Certifications & Compliance Frameworks

RecMan's compliance program is currently built around ISO/IEC 27001 and SOC 2, with GDPR compliance built into how we design and operate the solution.

ISO/IEC 27001

RecMan has held ISO/IEC 27001 certification continuously since 2021 (recertified under ISO/IEC 27001:2023), covering the support, consultation, development, and provision of the RecMan solution.

  • Scope: Covers the support, consultation, development, and provision of the RecMan software platform.
  • Certification body: Issued by Nemko Scandinavia AS (an IQNET-recognized certification body). Certificate authenticity can be verified independently at iqnet-certification.com.
  • Validity cycle: Operates on a 3-year cycle with annual surveillance audits. Our current certificate is valid through 2027-08-26 (Original issue date: 2021-08-26, maintained continuously with zero lapses).
  • Registration Number: NO-904088

The certificate itself is available for download here; the underlying Statement of Applicability (SoA) – which lists exactly which ISO 27001 controls we've implemented and how – is available under NDA on request.

SOC 2

RecMan has completed a SOC 2 Type I examination (as of June 30, 2024), performed by Boulay PLLP, covering the Security trust services category.

Key details for customer vendor risk assessments:

  • Report Type: SOC 2 Type I, not Type II. A Type I report assesses whether our controls are suitably designed at a single point in time. It does not test whether those controls operated effectively over a period of months, the way a Type II report would. We plan to pursue Type II certification in the future.
  • The publicly available report is not the full report. The version linked from our documentation page includes the auditor's opinion and management's assertion (Sections I–II), but excludes the detailed system description and control listing (Sections III–IV), which are shared only under NDA.
  • AWS is a subservice organization. Our SOC 2 report covers controls managed directly by RecMan and outlines complementary customer/subservice controls assumed at AWS. AWS maintains independent SOC 2 Type II and ISO 27001 certifications.

GDPR

RecMan is designed to support GDPR compliance:

  • Data residency: All core cloud infrastructure and default data processing activities take place exclusively within the EU/EEA.
  • Standard DPA: A Data Processing Agreement (DPA) is available for every customer at recman.io/privacy-and-terms/data-processing-agreement.
  • Third-party integrations: Customers can choose to activate optional third-party integrations within the RecMan platform. When enabled, data processed by these services is governed by the customer's own agreements with those third-party providers. Data processing and storage locations for integrated services depend directly on the customer's specific tenant setup and vendor configurations.
  • Legal and regulatory tracking: RecMan maintains a formal record of processing activities and legal obligations, reviewed at least annually.

PCI DSS

RecMan does not directly store, process, or transmit credit cardholder data on internal servers. All subscription billing and payment processing are delegated to a PCI DSS Level 1 certified payment gateway. RecMan completes an annual PCI DSS Self-Assessment Questionnaire (SAQ-A) and holds a signed Attestation of Compliance (AoC).

Google API

RecMan's Google integrations may access restricted Google API scopes, which requires ongoing compliance with Google's API Services User Data Policy, including its "Limited Use" requirements. To maintain this access, RecMan completes Google's CASA (Cloud Application Security Assessment) annually.

Other frameworks

RecMan aligns its practices with a number of widely recognized frameworks and standards even where we don't hold formal certification against them, including NIST guidelines (e.g., SP 800-53, SP 800-63B, SP 800-34), the CSA Cloud Controls Matrix, OWASP secure coding practices, and AWS/CIS security benchmarks. If a customer's questionnaire references a specific framework not covered here, our team can typically map our existing controls to it directly.

Documentation

Document Access
Terms of Service Public, see here
Privacy Policy Public, see here
Data Processing Agreement Public, see here
ISO 27001 certificate Public, see here
SOC 2 Type I Executive Summary Public, see here
ISO 27001 documentation (e.g., SoA) NDA required
Full SOC 2 Type I Report NDA required
Penetration test reports NDA required
Was this article helpful?
0 out of 0 found this helpful