RecMan's compliance program is currently built around ISO/IEC 27001 and SOC 2, with GDPR compliance built into how we design and operate the solution.
ISO/IEC 27001
RecMan has held ISO/IEC 27001 certification continuously since 2021 (recertified under ISO/IEC 27001:2023), covering the support, consultation, development, and provision of the RecMan solution.
- Scope: Covers the support, consultation, development, and provision of the RecMan software platform.
- Certification body: Issued by Nemko Scandinavia AS (an IQNET-recognized certification body). Certificate authenticity can be verified independently at iqnet-certification.com.
- Validity cycle: Operates on a 3-year cycle with annual surveillance audits. Our current certificate is valid through 2027-08-26 (Original issue date: 2021-08-26, maintained continuously with zero lapses).
- Registration Number: NO-904088
The certificate itself is available for download here; the underlying Statement of Applicability (SoA) – which lists exactly which ISO 27001 controls we've implemented and how – is available under NDA on request.
SOC 2
RecMan has completed a SOC 2 Type I examination (as of June 30, 2024), performed by Boulay PLLP, covering the Security trust services category.
Key details for customer vendor risk assessments:
- Report Type: SOC 2 Type I, not Type II. A Type I report assesses whether our controls are suitably designed at a single point in time. It does not test whether those controls operated effectively over a period of months, the way a Type II report would. We plan to pursue Type II certification in the future.
- The publicly available report is not the full report. The version linked from our documentation page includes the auditor's opinion and management's assertion (Sections I–II), but excludes the detailed system description and control listing (Sections III–IV), which are shared only under NDA.
- AWS is a subservice organization. Our SOC 2 report covers controls managed directly by RecMan and outlines complementary customer/subservice controls assumed at AWS. AWS maintains independent SOC 2 Type II and ISO 27001 certifications.
GDPR
RecMan is designed to support GDPR compliance:
- Data residency: All core cloud infrastructure and default data processing activities take place exclusively within the EU/EEA.
- Standard DPA: A Data Processing Agreement (DPA) is available for every customer at recman.io/privacy-and-terms/data-processing-agreement.
- Third-party integrations: Customers can choose to activate optional third-party integrations within the RecMan platform. When enabled, data processed by these services is governed by the customer's own agreements with those third-party providers. Data processing and storage locations for integrated services depend directly on the customer's specific tenant setup and vendor configurations.
- Legal and regulatory tracking: RecMan maintains a formal record of processing activities and legal obligations, reviewed at least annually.
PCI DSS
RecMan does not directly store, process, or transmit credit cardholder data on internal servers. All subscription billing and payment processing are delegated to a PCI DSS Level 1 certified payment gateway. RecMan completes an annual PCI DSS Self-Assessment Questionnaire (SAQ-A) and holds a signed Attestation of Compliance (AoC).
Google API
RecMan's Google integrations may access restricted Google API scopes, which requires ongoing compliance with Google's API Services User Data Policy, including its "Limited Use" requirements. To maintain this access, RecMan completes Google's CASA (Cloud Application Security Assessment) annually.
Other frameworks
RecMan aligns its practices with a number of widely recognized frameworks and standards even where we don't hold formal certification against them, including NIST guidelines (e.g., SP 800-53, SP 800-63B, SP 800-34), the CSA Cloud Controls Matrix, OWASP secure coding practices, and AWS/CIS security benchmarks. If a customer's questionnaire references a specific framework not covered here, our team can typically map our existing controls to it directly.
Documentation
| Document | Access |
|---|---|
| Terms of Service | Public, see here |
| Privacy Policy | Public, see here |
| Data Processing Agreement | Public, see here |
| ISO 27001 certificate | Public, see here |
| SOC 2 Type I Executive Summary | Public, see here |
| ISO 27001 documentation (e.g., SoA) | NDA required |
| Full SOC 2 Type I Report | NDA required |
| Penetration test reports | NDA required |