RELIANOID ISO/IEC 27017 & 27018 Compliance

Last Reviewed: July 2026
Next Review Due: July 2027

ISO/IEC 27017 & 27018 Compliance Statement

Cloud Security and Data Privacy Alignment for RELIANOID Platform and Organization

RELIANOID is aligned with the principles of both ISO/IEC 27017 (Cloud-specific security controls) and ISO/IEC 27018 (Protection of personal data in cloud environments). These standards guide our security, data protection, and operational practices for both our RELIANOID Load Balancer and our organization-wide processes.

While RELIANOID is not officially certified under ISO/IEC 27017 or 27018, we maintain security and data protection controls aligned with the relevant principles across our infrastructure, internal policies, vulnerability management processes, and customer-facing operations.

Cloud-Specific Security Practices (ISO/IEC 27017)

Responsibility Segregation

RELIANOID maintains defined security responsibilities across its organizational and technical operations. Security, data protection, access control, incident response, and third-party risk management are supported by documented policies and procedures that are reviewed regularly.

Identity & Access Management

Access control is a key component of RELIANOID’s security framework. 100% of employee accounts are protected by multi-factor authentication (MFA), while account lifecycle controls are maintained to prevent unnecessary or inactive accounts from remaining enabled.

Cloud Infrastructure and Network Security

RELIANOID maintains network security controls designed to protect communications between services and infrastructure. 100% of intra-service communications use private IPs, while services support SSL/TLS for secure communications.

RELIANOID also maintains network abuse IP protection and network DoS protection, together with Web Application Firewall (WAF) capabilities as part of its layered security approach.

Cloud Usage and Data Protection Policies

RELIANOID maintains formal policies covering data protection, business continuity, incident response, third-party risk management, and service-level management. These policies are reviewed on an annual basis and support the organization’s security and privacy commitments.

Data classification and retention practices are maintained according to the RELIANOID Data Processing Agreement (DPA), supporting controlled handling and retention of information processed within the organization’s operations.

Infrastructure Resilience

RELIANOID maintains tested backup and restoration processes to support operational resilience. Backup and restoration procedures are tested quarterly, while third-party infrastructure providers are assessed for availability, resilience, security certifications, and contingency capabilities.

Data Privacy by Design (ISO/IEC 27018)

Data Protection in Cloud Environments

RELIANOID maintains controls designed to protect data processed through its services and supporting infrastructure.

  • Encryption is applied to data in transit
  • Data classification and retention policies are maintained according to the Data Processing Agreement
  • Backup and restoration processes are tested quarterly
  • Third-party providers are assessed for security, resilience, and data protection considerations

RELIANOID’s current security assessment identifies encryption at rest as an area not currently implemented across the assessed environment. Data Loss Prevention (DLP) tooling and effectiveness are planned as a future security improvement.

Transparency and Client Control

RELIANOID maintains documented data protection and processing practices through its policies and Data Processing Agreement. Data classification and retention requirements are established according to the applicable DPA and organizational processes.

Access and Security Monitoring

Access controls are supported by mandatory MFA for employee accounts. RELIANOID also maintains alert accuracy and escalation procedures and performs incident and near-miss reviews.

Centralized log correlation through a Security Information and Event Management (SIEM) platform is currently planned as a future improvement to strengthen monitoring and detection capabilities.

Third-Party Confidentiality and Risk Management

RELIANOID maintains an inventory and risk assessment process for critical ICT suppliers. Third-party services are evaluated according to their security certifications, operational risks, SLA and resilience commitments, and available contingency plans.

Where appropriate, RELIANOID maintains alternative providers, backup systems, redundant infrastructure, or other contingency mechanisms to reduce dependency and support continuity of critical operations.

Organizational Practices Supporting Compliance

Employee Training and Awareness

RELIANOID maintains security awareness and training programs, tracks training completion, and updates security awareness training content. Phishing simulation exercises and the incorporation of new threat intelligence into security awareness content are identified as future improvement areas.

Incident Response

RELIANOID maintains documented Incident Response & Reporting Procedures and reviews incident response team contact information. Incident reviews and near-miss processes are in place.

Formal testing and review of the Incident Response Plan, together with systematic documentation and implementation of lessons learned, are identified as planned improvements within the security roadmap.

Vendor Risk Management

RELIANOID maintains a structured third-party risk management process covering critical ICT suppliers, security certifications, operational risks, SLAs, resilience commitments, and contingency plans.

Vulnerability and Security Monitoring

RELIANOID conducts regular vulnerability scanning, patch management, security monitoring, and service and product testing. The latest security assessment dated 29 June 2026 reported 104 vulnerabilities fixed and 15 vulnerabilities remaining to fix within product vulnerability monitoring.

Service and product security testing launched 1,007 tests, with findings tracked according to risk level and remediation requirements. These processes support continuous improvement of the security posture of RELIANOID’s products and services.

Commitment to Secure Cloud Operations

RELIANOID continues to enhance its security alignment with ISO/IEC 27017 and 27018 through:

  • Regular review of security and data protection policies
  • Continuous vulnerability scanning, security testing, and remediation
  • Strengthening access controls and MFA enforcement
  • Maintaining encryption for data in transit
  • Quarterly backup and restoration testing
  • Continuous assessment of critical third-party providers and their resilience
  • Planned improvements in SIEM-based centralized monitoring and DLP capabilities
  • Transparent documentation for customer security and compliance assessments

Trusted for Regulated Environments

RELIANOID supports clients operating in regulated sectors with:

  • Security documentation mapped to ISO/IEC 27017/27018 principles
  • Security and compliance information supporting customer assessments
  • Guidance for secure deployment and operational practices
  • Documentation covering data protection, vulnerability management, access controls, and third-party risk
  • Security and compliance documentation available for customer audits and assessments upon request

Document Reviews

DateComment
10th July 2025Initial publication of 27017 & 27018 alignment statement
30th June 2026Security and compliance review updated based on the RELIANOID Security Compliance Report 2026Q2

Contact and Assurance

We invite inquiries for detailed compliance documentation, technical mappings, and assistance in integrating RELIANOID within ISO-aligned infrastructures.

Contact our Compliance & Security Team

Download Latest Security Report