ssm.ro Docs
Compliance & Data ProtectionCompliance & Audit

Certifications and Standards

SSM.ro's ISO/IEC 27001 certification, applicable security standards, and infrastructure provider certifications

The SSM.ro platform holds ISO/IEC 27001 certification for its own information security management system and additionally relies on certified infrastructure providers.

SSM.ro Certification — ISO/IEC 27001

SSM.ro holds ISO/IEC 27001 certification, the international standard for the Information Security Management System (ISMS). The certification confirms that SSM.ro operates a documented, independently audited management system, which covers:

  • Information security policies and objectives
  • Risk assessment and treatment (see Risk Management)
  • Security controls per Annex A (access control, encryption, operations, suppliers, incidents, continuity)
  • Monitoring, internal audit, and continuous improvement

The certificate, its scope, and the Statement of Applicability (SoA) are available to clients and auditors upon request — see Reports Available to Clients.

Certifications Inherited from Providers

The underlying infrastructure benefits from the managed providers' certifications:

ProviderTypical Certifications
AWSISO 27001, ISO 27017/27018, SOC 1/2/3, PCI DSS (at the infrastructure level)
Heroku (Salesforce)ISO 27001, SOC 1/2/3 (at the platform level)

These certifications cover the infrastructure and platform layers on which SSM.ro runs.

Implemented Controls

In addition to ISO/IEC 27001 certification, SSM.ro also aligns its own controls with SOC 2 criteria (security, availability, confidentiality). Key controls include:

  • RBAC access control and tenant isolation
  • Encryption in transit and at rest
  • Risk and vulnerability management
  • Backup, continuity, and incident response
  • Tamper-evident audit trail for signatures

Qualified Electronic Signature

Signatures are issued through a trusted electronic signature provider, qualified (QTSP) under the eIDAS Regulation (EU 910/2014) — the signatures produced are qualified electronic signatures with legal validity.

Note

The ISO/IEC 27001 certificate, its scope, and audit documents available to clients are provided by the compliance team upon request — see Reports Available to Clients.