Certifications and Standards
SSM.ro's ISO/IEC 27001 certification, applicable security standards, and infrastructure provider certifications
The SSM.ro platform holds ISO/IEC 27001 certification for its own information security management system and additionally relies on certified infrastructure providers.
SSM.ro Certification — ISO/IEC 27001
SSM.ro holds ISO/IEC 27001 certification, the international standard for the Information Security Management System (ISMS). The certification confirms that SSM.ro operates a documented, independently audited management system, which covers:
- Information security policies and objectives
- Risk assessment and treatment (see Risk Management)
- Security controls per Annex A (access control, encryption, operations, suppliers, incidents, continuity)
- Monitoring, internal audit, and continuous improvement
The certificate, its scope, and the Statement of Applicability (SoA) are available to clients and auditors upon request — see Reports Available to Clients.
Certifications Inherited from Providers
The underlying infrastructure benefits from the managed providers' certifications:
| Provider | Typical Certifications |
|---|---|
| AWS | ISO 27001, ISO 27017/27018, SOC 1/2/3, PCI DSS (at the infrastructure level) |
| Heroku (Salesforce) | ISO 27001, SOC 1/2/3 (at the platform level) |
These certifications cover the infrastructure and platform layers on which SSM.ro runs.
Implemented Controls
In addition to ISO/IEC 27001 certification, SSM.ro also aligns its own controls with SOC 2 criteria (security, availability, confidentiality). Key controls include:
- RBAC access control and tenant isolation
- Encryption in transit and at rest
- Risk and vulnerability management
- Backup, continuity, and incident response
- Tamper-evident audit trail for signatures
Qualified Electronic Signature
Signatures are issued through a trusted electronic signature provider, qualified (QTSP) under the eIDAS Regulation (EU 910/2014) — the signatures produced are qualified electronic signatures with legal validity.
Note
The ISO/IEC 27001 certificate, its scope, and audit documents available to clients are provided by the compliance team upon request — see Reports Available to Clients.