
ISO/IEC 27001
Information security management system covering all managed services.
CERTIFIED · RENEWED 2026
We hold our own certifications and map every control we operate on your behalf back to the frameworks your auditor cares about.

Information security management system covering all managed services.
CERTIFIED · RENEWED 2026

Privacy information management extension for personal-data processing.
CERTIFIED

Security, availability and confidentiality trust service criteria.
ATTESTED · ANNUAL

Qualified to support cardholder-data environment monitoring.
SERVICE PROVIDER LEVEL 1

Licensed cybersecurity service provider under national regulation.
LICENSED

Data processing agreements and in-region residency guarantees.
COMPLIANT

Control mapping and maturity assessment for client programmes.
ALIGNED

Industrial automation and control system security for OT engagements.
ALIGNED
| CONTROL DOMAIN | ISO 27001 ANNEX A | SOC 2 CRITERIA | NIST CSF 2.0 | DEGOOL COVERAGE |
|---|---|---|---|---|
| Identity & access management | A.5.15–A.5.18 | CC6.1–CC6.3 | PR.AA | |
| Threat detection & monitoring | A.8.15–A.8.16 | CC7.2 | DE.CM | |
| Incident response | A.5.24–A.5.28 | CC7.3–CC7.5 | RS.MA | |
| Vulnerability management | A.8.8 | CC7.1 | ID.RA | |
| Configuration & change control | A.8.9, A.8.32 | CC8.1 | PR.PS | |
| Data protection & encryption | A.8.24 | CC6.7 | PR.DS | |
| Supplier & third-party risk | A.5.19–A.5.22 | CC9.2 | GV.SC | |
| Logging & audit evidence | A.8.15 | CC4.1 | DE.AE | |
| Business continuity | A.5.29–A.5.30 | A1.2 | RC.RP |
Two-week assessment: we ingest your existing logs, run the Sentinel detection pack, and hand back a prioritised findings report. No agents, no commitment.