Trust & certifications

Security & compliance

Versiro is certified to ISO/IEC 27001:2022 — the international standard for information security management — by Bureau Veritas Certification Finland.

Protecting the data behind electricity-market decisions is core to what we do. Versiro's information security management system (ISMS) is independently certified to ISO/IEC 27001:2022, the leading international standard for establishing, operating and continually improving information security.

Standard
ISO/IEC 27001:2022
Certified organization
Versiro
Certification body
Bureau Veritas Certification Finland
Scope
Software services for analytics, optimization, and financial operations in electrical power systems.
Certificate & reports
Available in our Trust Center.

Our ISMS covers 58 controls, grouped as below. Each control's description and its current status are published in our Trust Center.

Infrastructure security 15

  • Information backup
  • Identity management
  • Access rights
  • Privileged access rights
  • Secure authentication
  • Logging
  • Monitoring activities
  • Networks security
  • Security of network services
  • Segregation of networks
  • Redundancy of information processing facilities
  • Application security requirements
  • Separation of development, test and production environments
  • Information security in supplier relationships
  • Management of technical vulnerabilities

Organizational security 13

  • Planning of Changes
  • Change management
  • Internal Audit - General
  • Nonconformity and corrective action
  • Legal, statutory, regulatory and contractual requirements
  • Compliance with policies, rules and standards for information security
  • Leadership and commitment
  • Contact with special interest groups
  • Information security roles and responsibilities
  • Competence
  • Confidentiality or non-disclosure agreements
  • Outsourced development
  • Contact with authorities

Data and privacy 14

  • Compliance with policies, rules and standards for information security
  • Use of cryptography
  • Protection of records
  • Information deletion
  • Data masking
  • Data leakage prevention
  • Protection against malware
  • Policies for information security
  • Access control
  • Information access restriction
  • Addressing information security within supplier agreements
  • Privacy and protection of PII
  • Inventory of information and other associated assets
  • Information security for use of cloud services

Internal security procedures 16

  • ICT readiness for business continuity
  • Independent review of information security
  • Segregation of duties
  • Response to information security incidents
  • Information security during disruption
  • Information security event reporting
  • Information security in project management
  • Information security risk assessment
  • Information security risk treatment
  • Information security awareness, education and training
  • Secure system architecture and engineering principles
  • Secure development life cycle
  • Secure coding
  • Security testing in development and acceptance
  • Threat Intelligence
  • Managing information security in the ICT supply chain
  • Data is processed only within the EU/EEA. This includes data processed by our subprocessors.
  • Versiro follows the principles and obligations of the GDPR and the Norwegian Personal Data Act.
  • Versiro follows the principles and obligations of the EU's Artificial Intelligence Act.

We use a small number of subprocessors, all of which process data within the EU/EEA:

Azure
Cloud provider
Cloudflare
Hosting and content delivery
HubSpot
Marketing
PostHog
Data analytics

Our ISO 27001:2022 certificate, and the itemised list of the controls in our ISMS with their current status, are published in our Trust Center. Our security policies — covering access control, data management, operations security, third-party management, risk management, business continuity and our code of conduct — along with our most recent penetration test report, are available there on request.

If you believe you have found a security vulnerability or want to report a potential security issue, please contact us at contact@versiro.com.