> ## Documentation Index
> Fetch the complete documentation index at: https://docs.threataware.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Certifications

> ISO 27001, Cyber Essentials, GDPR — Protect's compliance posture

## Active certifications

| Standard             | Status         | Scope                                                                                         | Cadence                                              |
| -------------------- | -------------- | --------------------------------------------------------------------------------------------- | ---------------------------------------------------- |
| **ISO 27001**        | Certified      | Information security management system (ISMS) covering all Protect engineering and operations | Annual surveillance audit; triennial recertification |
| **Cyber Essentials** | Certified (UK) | UK Government cyber baseline                                                                  | Annual                                               |
| **GDPR**             | Compliant      | Data protection by design across all Protect data flows                                       | Continuous                                           |

Audit reports and Statements of Applicability are available under NDA — contact your account manager.

## How Protect helps your compliance

Protect's job is to **demonstrate** your security controls work, which directly supports your own compliance posture:

<Tabs>
  <Tab title="ISO 27001 (yours)">
    | Control                               | How Protect helps                                                     |
    | ------------------------------------- | --------------------------------------------------------------------- |
    | **A.5.9** — Inventory of assets       | Continuous, accurate device inventory                                 |
    | **A.5.10** — Acceptable use           | Tag-based controls; device classification                             |
    | **A.5.16** — Identity management      | User Inventory + access reviews                                       |
    | **A.5.17** — Authentication info      | Multi-Factor Authentication (MFA) tracking via Entra/Okta integration |
    | **A.5.23** — Cloud services           | Cloud integrations + monitoring                                       |
    | **A.5.25** — Threat intelligence      | Issues feed + Endpoint Detection and Response (EDR) data              |
    | **A.8.1** — User endpoints            | Device inventory + Vitals                                             |
    | **A.8.7** — Malware protection        | EDR Vitals + Issues                                                   |
    | **A.8.8** — Technical vulnerabilities | Vulnerability scanner integration                                     |
    | **A.8.16** — Monitoring activities    | Audit log + automation log                                            |
  </Tab>

  <Tab title="NIST CSF">
    | Function     | How Protect helps                                          |
    | ------------ | ---------------------------------------------------------- |
    | **Identify** | Asset and software inventory across estate                 |
    | **Protect**  | Vitals validate controls are deployed + functioning        |
    | **Detect**   | Issues + broken-agent detection via cross-tool correlation |
    | **Respond**  | Action Center automated remediation                        |
    | **Recover**  | Audit log + historical state                               |
  </Tab>

  <Tab title="Cyber Essentials (UK)">
    | Requirement                   | How Protect helps                               |
    | ----------------------------- | ----------------------------------------------- |
    | **Firewalls**                 | Firewall state Vital (where exposed by EDR/MDM) |
    | **Secure configuration**      | Configuration check Vitals                      |
    | **User access control (MFA)** | MFA enrolment tracking                          |
    | **Malware protection**        | EDR coverage + functioning checks               |
    | **Patch management**          | Patch SLA tracking + Actions                    |
  </Tab>

  <Tab title="CIS Controls">
    | Control                       | How Protect helps                     |
    | ----------------------------- | ------------------------------------- |
    | **1** — Inventory of devices  | Cross-tool deduplicated inventory     |
    | **2** — Inventory of software | Software inventory per tag            |
    | **3** — Data protection       | Encryption Vitals                     |
    | **4** — Secure configuration  | Config-check Vitals                   |
    | **5** — Account management    | User Inventory + offboarding tracking |
    | **6** — Access control        | Authentication + MFA Vitals           |
    | **8** — Audit log management  | Native audit log + SIEM integration   |
    | **10** — Malware defenses     | EDR Vitals + Issues                   |
    | **18** — Penetration testing  | Vulnerability scanner integration     |
  </Tab>

  <Tab title="PCI DSS">
    | Requirement                             | How Protect helps                 |
    | --------------------------------------- | --------------------------------- |
    | **5** — Anti-malware                    | EDR coverage + functioning        |
    | **6** — Vulnerability management        | Vulnerability scanner integration |
    | **7** — Access control                  | User Inventory + roles            |
    | **8** — Identification + authentication | MFA tracking                      |
    | **10** — Logging                        | Audit log                         |
    | **11** — Security testing               | Vulnerability scanner integration |
  </Tab>
</Tabs>

## What Protect doesn't certify

Protect's certifications cover the Protect platform itself. They don't:

* Replace your own ISO 27001 certification — Protect supports it, doesn't substitute for it
* Cover your endpoint devices — that's the job of your EDR / MDM
* Cover data processed in tools Protect connects to — those tools have their own compliance

Use Protect as evidence in your own audits, not as the certification itself.

## Audit support

For your own audits / external assessments:

| Need                         | How                                                                                                       |
| ---------------------------- | --------------------------------------------------------------------------------------------------------- |
| **Auditor read-only access** | Create a [custom role](/settings/roles) with view-only permissions; create a user with an expiration date |
| **Evidence pack**            | Export [Audit Log](/settings/audit-log) for the audit period; export saved-view evidence as CSV/PDF       |
| **Control narrative**        | Use the canonical mapping tables above as a starting template                                             |
| **DPA**                      | Standard data-processing agreement available; contact your account manager                                |
| **Penetration test summary** | Annual independent test report; executive summary on request                                              |

## Data residency

* **Default**: UK (London region)
* **Other regions**: Available on request; lead time varies

If your regulatory environment requires data in a specific jurisdiction, raise the requirement with your account manager during procurement.

## Contact

| Topic                    | Channel                                                        |
| ------------------------ | -------------------------------------------------------------- |
| Audit reports / SOA      | [help@threataware.com](mailto:help@threataware.com) → DPA team |
| Subprocessor disclosures | [help@threataware.com](mailto:help@threataware.com)            |
| Security questionnaires  | Your account manager                                           |
| Security disclosures     | [security@threataware.com](mailto:security@threataware.com)    |

## See also

<CardGroup cols={3}>
  <Card title="Security & Privacy" icon="shield-check" href="/trust/security">
    Top-level posture
  </Card>

  <Card title="Architecture" icon="diagram-project" href="/trust/architecture">
    Technical deep dive
  </Card>

  <Card title="Audit Log" icon="clipboard-list" href="/settings/audit-log">
    Evidence source
  </Card>
</CardGroup>
