Skip to content
Assurance & Compliance Architecture

Your risk officer's questions, answered before they are asked.

Security review is where most vendor evaluations stall. Ours is published, in full, with raw evidence and an active accredited ISO/IEC 27001:2022 certificate.

Primary Credential · Audited Standard Held

Trust, but verify. You are in safe hands.

TechLand Engineering holds one certificate: ISO/IEC 27001:2022, issued by UKS Egypt, covering our engineering, workflow automation and AI work. The other seventeen standards below are ones we practise, and each one says so. Check any of it before you call us.

Primary Standard Held·Audited & Current

ISO/IEC 27001:2022

Information Security Management System (ISMS) · Independently audited and registered under international accreditation.

Certificate NumberUKS-ISMS-25-051Registrar registry entry
Certification BodyUKS EgyptEGAC, CAB 012415
Validity Window4 Sept 2026 – 3 Sept 20293-year cycle · Annual surveillance
AccreditationEGAC, CAB 012415Scope includes remote personnel
Certified Scope of RegistrationVerbatim Accredited Schedule

“The design, development, testing, deployment, support and maintenance of custom software, web applications, workflow automation and AI-enabled applications, including the integration, training and deployment of machine learning and generative AI models, and the secure software development lifecycle, delivered from the organisation's premises and by personnel working remotely, together with the supporting corporate IT, human resources and administrative functions.”

Operational Assurance & Production Frameworks

Controls we operate in production.

Everything above is certified by an accredited registrar. Everything below is an engineering control we operate and enforce in CI/CD, testing, and production. Where frameworks issue no certificate to anyone (such as OWASP, SLSA, or NIST), we supply verifiable engineering artifacts: raw SBOMs, automated build attestations, and executive penetration test reports.

Information security

3 Practised Controls
SOC 2 · TSCControls mapped to Security, Availability, Confidentiality
CIS Controls v8.1Implementation Group 2 baseline
ISO 22301Continuity plan with tested recovery objectives

Application & supply chain

5 Practised Controls
OWASP ASVS 5.0Level 2 verification on every release
OWASP Top 10 · API Top 10Regression-tested per release
OWASP SAMM 2SDLC maturity assessed annually
SLSA v1.0Build Level 2 provenance on release artifacts
CycloneDX SBOMIssued with every build

Data protection & privacy

4 Practised Controls
GDPRDPA, DSAR workflow, EU residency on request
ISO/IEC 27701:2019Privacy extension to the ISMS
HIPAABAA available; PHI under technical safeguards
PCI DSS v4.0No cardholder data at rest; SAQ-D aware integrations

Quality, delivery & AI governance

5 Practised Controls
ISO 9001:2015Quality management system operated
ISO/IEC 42001:2023AI management system operated
NIST AI RMF 1.0Applied to every model deployment
WCAG 2.2 AAConformance target on every interface
ISO/IEC 25010Quality model used in acceptance criteria

Everything above the certificate is audited. Everything below it is a control we operate, and most of those frameworks issue no certificate to anyone, so nobody can hold one. Ask us for the artifact instead: the SBOM, the penetration test summary, the pipeline run.

What the marks resolve to.

Ten domains, the evidence available for each, and the ISO/IEC 27001 Annex A controls they map to. Your auditor can check this against their own register without asking us for anything.

TechLand Engineering control register: what we operate in each domain, the evidence available on request, and the ISO/IEC 27001 Annex A controls each domain maps to.
DomainWhat we operateEvidence availableISO 27001 Annex A
Access controlSSO with enforced MFA, least-privilege roles, quarterly access review, offboarding within one business dayAccess control policyA.5.15, A.5.16, A.5.18, A.8.2, A.8.5
EncryptionTLS 1.3 in transit, AES-256 at rest, customer-managed keys where the platform supports itArchitecture noteA.8.24
Secure developmentPeer review on every merge, SAST and dependency scanning in CI, ASVS L2 checklist at releaseSDLC policy, sample pipeline runA.8.25, A.8.26, A.8.28, A.8.29, A.8.31
Penetration testingIndependent test before each major release and annually thereafterExecutive summary under NDAA.8.8, A.8.29
Supply chainPinned dependencies, signed builds, SBOM per release, CVE triage within a stated windowSBOM, provenance attestationA.5.19, A.5.20, A.5.21, A.8.30
Incident responseNamed on-call, severity ladder, customer notification commitment in writingIR plan, notification SLAA.5.24, A.5.25, A.5.26, A.6.8
Business continuityDocumented RTO and RPO per system, restore tested rather than assumedBCP, last restore test dateA.5.29, A.5.30, A.8.13, A.8.14
Data protectionProcessing register, retention schedule, DSAR workflow, residency optionsDPA, sub-processor listA.5.33, A.5.34, A.8.10, A.8.11
AI governanceModel inventory, human review on consequential decisions, no client data into third-party trainingAI use policy
PeopleBackground checks where law allows, NDAs, annual security training with completion trackedTraining records summaryA.6.1, A.6.2, A.6.3, A.6.6