Security & Compliance
Trust, engineered in.
We run security and compliance to the same standard we build for our customers.
Trust
Certifications & accreditations
- ISO/IEC 27001
- SOC 2 Type II
- ISO 9001
- ISO/IEC 20000-1
- ISO/IEC 27701
- ISO 22301
- ISO/IEC 42001
- ISO 14001
- ISO 45001
- CREST Accreditation
- DISP Membership
- PCI DSS Compliance
- Essential Eight ML2
- Essential Eight ML3
Practices
How we protect your data and systems.
Least privilege
Access to customer systems is role-based, time-bound where possible, and reviewed.
Strong identity
Multi-factor authentication and single sign-on across the systems we use to deliver.
Encryption
Data encrypted in transit and at rest across the platforms we build and operate.
Secure engineering
Code review, dependency management, secrets management and security testing in delivery.
Monitoring & response
Logging, alerting and a defined incident-response process with customer notification.
Supplier assurance
Vendors and sub-processors assessed before use and reviewed over time.
Reporting a vulnerability
If you believe you've found a security issue in a Sarja website or service, email support@sarja.dev with “Security report” in the subject. Please give us reasonable time to investigate before disclosing it publicly, and don't access data that isn't yours.
Documentation requests
Customers and prospective customers can request certificates, reports and security questionnaires through their Sarja contact or by emailing us. Some documents are provided under a non-disclosure agreement.
Security questions before you engage?
Talk to us about your requirements, frameworks and assurance needs.