1 Certification summary
| Standard | ISO/IEC 27001:2022 (Information security, cybersecurity and privacy protection — Information security management systems — Requirements) |
| Status | Certified |
| Scope | The information security management system supporting the Headx Monitor platform — Cloud (SaaS, AWS ap-south-1) and On-Premise delivery. |
| Certificate | Available from sales on request |
| Certification cycle | Three-year cycle with annual surveillance audits by an accredited certification body |
2 Controls implemented
All Annex A controls applicable to Headx Monitor's scope are implemented and operating across the four control themes:
Organisational controls (Clause 5)
- Information security policy approved and reviewed annually
- Roles and responsibilities defined (CISO, DPO, security operations)
- Segregation of duties between development and production access
- Contact with authorities (CERT-In, sector regulators)
- Threat intelligence subscription and integration
- Information security in project management — security-review gate on every release
- Information transfer policies (with sub-processors, with customers)
- Access control policy with RBAC + named privilege escalation
People controls (Clause 6)
- Background verification for all employees
- Terms and conditions of employment include confidentiality obligations
- Disciplinary process for information security violations
- Information security awareness training — onboarding + annual refresh
- Remote working security policy
- Reporting of information security events workflow
Physical controls (Clause 7)
- Physical security perimeters at office locations
- Physical entry controls (access cards, visitor management)
- Security of offices, rooms, facilities
- Secure disposal or reuse of equipment
- Equipment maintenance and decommissioning procedures
- Production infrastructure AWS-hosted; AWS ap-south-1 physical controls inherited via the Shared Responsibility model
Technological controls (Clause 8)
- User access provisioning, review, and revocation
- Privileged access management (just-in-time, time-boxed)
- Information access restriction (need-to-know + RBAC)
- Secure authentication (bcrypt, lockouts, session timeouts)
- Capacity management with auto-scaling
- Protection against malware (EDR on all endpoints)
- Backup and recovery — daily full, hourly incremental, cross-AZ replication
- Logging and monitoring — centralised, SIEM-ready, anomaly detection
- Networks security (Cloudflare WAF, private subnets, egress controls)
- Cryptography — TLS 1.3, AES-256, KMS key management, quarterly key rotation
- Secure development life cycle
- Application security testing — SAST, SCA, DAST, annual external pen test
- Test data management — production data is never used in development or test
- Change management — approval workflow, rollback procedures
- Vulnerability management — daily SCA, monthly scans, CVE-based patch SLAs
The full Statement of Applicability (Annex A control-by-control with implementation evidence) is available under NDA.
3 Surveillance & recertification
ISO/IEC 27001 certification is maintained on a three-year cycle. The certification body conducts annual surveillance audits to confirm the ISMS continues to operate effectively, with a full recertification audit at the end of each cycle.
| Activity | Frequency |
|---|---|
| Internal ISMS audit | Annual (full scope) |
| Management review | Quarterly |
| External surveillance audit | Annual |
| Recertification audit | Every three years |
4 Documents available
The certificate is available directly; the following supporting artefacts are available under signed NDA, typically within 24 hours of request:
- ISO/IEC 27001:2022 certificate — available on request
- Statement of Applicability (SoA) — control-by-control applicability and implementation evidence
- ISMS scope statement — what is in / out of certification scope
- Information security policy — board-approved, current version
- Risk assessment and treatment plan — current risk register
- Internal audit report — latest internal audit findings and closure status
- Management review minutes — quarterly
- Penetration test executive summary — latest annual external test
- Sub-processor register with annual review records
Request via info@headx.in.
5 Other certifications
| Standard | Status | Notes |
|---|---|---|
| ISO/IEC 27001:2022 | Certified | This page |
| SOC 2 Type I | Certified | Trust services criteria; report available on request |
| GDPR | DPA template available | Available now |
| HIPAA | BAA available on request | Healthcare-adjacent customers |
| DPDP Act 2023 (India) | Aligned | See DPDP status |
| PCI DSS | Out of scope | Payment flows handled by Cashfree / Razorpay |
6 Contact
- Security / certification questions: info@headx.in
- Certificate & audit-evidence requests: info@headx.in
- Legal / DPA / contract: info@headx.in
- Sales / pre-procurement questionnaires: info@headx.in
Related documents
- Security Architecture — full technical security documentation
- Security & Compliance overview — at-a-glance security posture
- DPDP Act 2023 Compliance Status
- Privacy Policy
- Terms of Service
Need detailed audit evidence or a signed DPA?
The full Statement of Applicability, latest penetration-test summary, sub-processor register with annual review records, and pre-filled CAIQ / SIG questionnaires are available under NDA — typically within 24 hours (IST business days).