Security & compliance
Versiro is certified to ISO/IEC 27001:2022 — the international standard for information security management — by Bureau Veritas Certification Finland.
Protecting the data behind electricity-market decisions is core to what we do. Versiro's information security management system (ISMS) is independently certified to ISO/IEC 27001:2022, the leading international standard for establishing, operating and continually improving information security.
- Standard
- ISO/IEC 27001:2022
- Certified organization
- Versiro
- Certification body
- Bureau Veritas Certification Finland
- Scope
- Software services for analytics, optimization, and financial operations in electrical power systems.
- Certificate & reports
- Available in our Trust Center.
Our ISMS covers 58 controls, grouped as below. Each control's description and its current status are published in our Trust Center.
Infrastructure security 15
- Information backup
- Identity management
- Access rights
- Privileged access rights
- Secure authentication
- Logging
- Monitoring activities
- Networks security
- Security of network services
- Segregation of networks
- Redundancy of information processing facilities
- Application security requirements
- Separation of development, test and production environments
- Information security in supplier relationships
- Management of technical vulnerabilities
Organizational security 13
- Planning of Changes
- Change management
- Internal Audit - General
- Nonconformity and corrective action
- Legal, statutory, regulatory and contractual requirements
- Compliance with policies, rules and standards for information security
- Leadership and commitment
- Contact with special interest groups
- Information security roles and responsibilities
- Competence
- Confidentiality or non-disclosure agreements
- Outsourced development
- Contact with authorities
Data and privacy 14
- Compliance with policies, rules and standards for information security
- Use of cryptography
- Protection of records
- Information deletion
- Data masking
- Data leakage prevention
- Protection against malware
- Policies for information security
- Access control
- Information access restriction
- Addressing information security within supplier agreements
- Privacy and protection of PII
- Inventory of information and other associated assets
- Information security for use of cloud services
Internal security procedures 16
- ICT readiness for business continuity
- Independent review of information security
- Segregation of duties
- Response to information security incidents
- Information security during disruption
- Information security event reporting
- Information security in project management
- Information security risk assessment
- Information security risk treatment
- Information security awareness, education and training
- Secure system architecture and engineering principles
- Secure development life cycle
- Secure coding
- Security testing in development and acceptance
- Threat Intelligence
- Managing information security in the ICT supply chain
- Data is processed only within the EU/EEA. This includes data processed by our subprocessors.
- Versiro follows the principles and obligations of the GDPR and the Norwegian Personal Data Act.
- Versiro follows the principles and obligations of the EU's Artificial Intelligence Act.
We use a small number of subprocessors, all of which process data within the EU/EEA:
- Azure
- Cloud provider
- Cloudflare
- Hosting and content delivery
- HubSpot
- Marketing
- PostHog
- Data analytics
Our ISO 27001:2022 certificate, and the itemised list of the controls in our ISMS with their current status, are published in our Trust Center. Our security policies — covering access control, data management, operations security, third-party management, risk management, business continuity and our code of conduct — along with our most recent penetration test report, are available there on request.
If you believe you have found a security vulnerability or want to report a potential security issue, please contact us at contact@versiro.com.