RELIANOID ISO/IEC 27001 Compliance

Last Reviewed: July 2026
Next Review Due: July 2027

ISO/IEC 27001 Compliance Statement

Security Alignment for RELIANOID Load Balancer and Organizational Operations

At RELIANOID, we understand that our clients—spanning financial institutions, healthcare providers, public sector entities, and enterprise organizations—depend on secure, reliable infrastructure for mission-critical operations. That’s why we’ve made security, compliance, and resilience a core part of our DNA.

While RELIANOID is not currently ISO/IEC 27001 certified, our organization and load balancing platform are strongly aligned with the ISO/IEC 27001:2022 Information Security Management System (ISMS) framework and its Annex A controls. This alignment ensures our clients benefit from rigorous security principles and controls that support secure, resilient, and continuously improving operations.

Organizational Security Alignment

RELIANOID maintains a comprehensive set of policies, controls, and processes that map directly to ISO/IEC 27001 domains, including:

Governance & Risk Management

Our organization maintains an actively updated ICT and cyber risk register, with risk items mapped to ISO/IEC 27001 and other applicable security frameworks. Risks are tracked through documented controls, vulnerability management processes, remediation plans, and sprint backlogs.

As of 30 June 2026, identified medium- and high-risk findings have been tracked through formal remediation processes. Several identified risks have been resolved, while remaining high- and medium-risk application security findings are being addressed through the 2026 Q3 sprint backlog.

Security Policy Framework

Security-related policies—including Business Continuity and Disaster Recovery, Data Protection, Incident Response, Third-Party Risk Management, and Service Level Management—are maintained and reviewed annually.

The latest policy review cycle confirms current status for the principal security and operational policies, with the next annual reviews scheduled throughout 2027.

Security Awareness & Training

RELIANOID maintains security awareness and training programs, tracks training completion, and updates security awareness training content.

Phishing simulations and incorporation of new threat intelligence into awareness content remain areas identified for future improvement.

Incident Response

RELIANOID maintains documented incident response and reporting procedures, with incident response team contact information reviewed and maintained.

Incident review and near-miss processes are in place. Formal review and testing of the Incident Response Plan and systematic implementation of lessons learned are identified as planned areas for further improvement.

Third-Party Risk Management

As part of our ISO-aligned vendor risk strategy, RELIANOID maintains an inventory of critical ICT suppliers, assesses security certifications and risks, reviews service-level commitments, and maintains contingency plans for key services.

Third-party resilience measures include backup systems, redundant infrastructure, alternative providers, and the ability to transition services where required.

RELIANOID Platform Security

The RELIANOID Load Balancer is built for both on-premises and cloud environments, with security integrated into its architecture and software development lifecycle:

Secure Development Lifecycle (SSDLC)

Our product development lifecycle includes SSDLC enforcement, automated security scanning on every commit, third-party library vulnerability monitoring, and automated testing.

For the RELIANOID product, SAST/DAST scanning is automated on every commit, third-party libraries are monitored through weekly vulnerability scans, and automated tests are executed daily. Test coverage is also tracked for both Community and Enterprise editions.

For RELIANOID services, SSDLC enforcement is in place, while automated SAST/DAST scanning remains planned as a future improvement.

Encryption & Data Protection

RELIANOID protects communications through encryption in transit and maintains data classification and retention policies according to the Data Processing Agreement (DPA).

Backup and restoration processes are tested quarterly to support data resilience. Encryption at rest is not currently reported as implemented. DLP tooling and effectiveness are planned as a future improvement.

Access Controls

100% of RELIANOID workforce accounts are protected by multi-factor authentication.

The latest security review reports zero accounts requiring removal, supporting effective account lifecycle management and access control practices.

Infrastructure and Network Security

  • 100% of intra-service communications use private IPs
  • 100% of services support SSL/TLS
  • 5% of services currently operate without SSL/TLS and are identified as open and public services without associated risk
  • Network abuse IP protection and network DoS protection are implemented
  • Web Application Firewall (WAF) protection is implemented
  • RELIANOID maintains an SSL Labs Security Report rating of A+

Vulnerability Management and Testing

RELIANOID conducts regular vulnerability scanning, patch management, product security monitoring, and service and product pentesting.

The latest product vulnerability monitoring, performed on 29 June 2026, reported 104 vulnerabilities fixed and 15 vulnerabilities remaining to fix. The overall risk level for product vulnerability monitoring was classified as Critical, with software updates communicated and applied on every release according to the established timeline.

The latest service and product pentesting and scanning activity, also dated 29 June 2026, launched 1,007 tests. The overall risk level was High, with 16 high-risk findings, 12 medium-risk findings, 43 low-risk findings, and 89 informational findings. The report identifies 15 of the high-risk findings and one medium-risk finding as false positives, with remediation review scheduled for 1 October 2026.

Monitoring and Detection

RELIANOID maintains alert accuracy and escalation procedures and reviews incidents and near misses.

Centralized log correlation through a SIEM is not currently implemented and is planned as a future improvement. DLP tooling and effectiveness are also planned for a future stage of the security roadmap.

Commitment to Continuous Improvement

RELIANOID views compliance not as a checkbox—but as a continuous, evolving journey. We are committed to:

  • Continuously mapping internal practices and security controls to ISO/IEC 27001 and relevant cybersecurity frameworks
  • Investing in new controls, automation, and security testing to further reduce risk
  • Maintaining structured vulnerability management and remediation processes
  • Supporting client audits and vendor assessments with transparency and appropriate documentation
  • Strengthening monitoring, detection, incident response, and security awareness capabilities as part of our continuous improvement roadmap
  • Ensuring our platform remains resilient and secure as deployment models evolve

Supporting Regulated Environments

Whether deployed in government, financial, healthcare, or enterprise settings, RELIANOID provides a security-focused foundation for application delivery. We support regulated clients with:

  • SLA-backed support agreements
  • Pre-filled security questionnaires
  • Tailored guidance on deploying RELIANOID in ISO-aligned or certified infrastructures
  • Documentation packages for internal or external audits upon request
  • Security and compliance documentation covering our organizational and product controls

Document Reviews

DateComment
10th July 2025Document creation
30th June 2026Security and compliance review updated based on the RELIANOID Security Compliance Report 2026Q2

Contact and Assurance

We welcome requests for detailed security documentation, risk mapping matrices, or compliance disclosures.

Contact our Compliance & Security Team

Download Latest Security Report