RELIANOID ISO/IEC 27033 Compliance

Last Reviewed: July 2026

Next Review Due: July 2027

ISO/IEC 27033 Compliance Statement

RELIANOID Load Balancer is a secure application delivery controller designed for on-premises and cloud environments. While RELIANOID is not currently certified under ISO/IEC 27033, our organization and product security practices are aligned with its principles for network security, secure communications, access control, and resilient infrastructure.

Organizational Alignment with ISO/IEC 27033

RELIANOID integrates network security principles into its broader security governance and operational framework. Our controls include private IP usage for intra-service communications, SSL/TLS support, network abuse protection, network DoS protection, access controls, vulnerability management, and documented incident response procedures.

These practices are supported by an ICT and cyber risk register, formal security policies, vulnerability management processes, and continuous security testing.

Network Architecture Security Details

RELIANOID supports secure network architectures for application delivery across different deployment environments. The latest security assessment confirms that 100% of intra-service communications use private IPs, supporting network separation and controlled internal service communication.

Services support SSL/TLS, while network abuse IP protection, network DoS protection, and Web Application Firewall (WAF) protection provide additional layers of network and application security.

Key Network Security Measures

  • Secure Architecture: 100% of intra-service communications use private IPs, supporting controlled communication between internal services.
  • Transport Layer Security: 100% of assessed services support SSL/TLS. The RELIANOID security assessment also reports an SSL Labs Security Report rating of A+.
  • Access Control: 100% of employee accounts are protected by multi-factor authentication (MFA).
  • Application Security: Secure Software Development Lifecycle (SSDLC), automated security testing, and vulnerability monitoring are implemented.
  • Network Protection: Network abuse IP protection and network DoS protection are implemented.
  • Web Application Protection: Web Application Firewall (WAF) protection is implemented.

Alignment with ISO/IEC 27033 Core Domains

  • Security Architecture: RELIANOID applies layered network and application security controls, including private IP usage for intra-service communication, SSL/TLS support, and network protection mechanisms.
  • Network Protection: Network abuse IP protection and network DoS protection are implemented as part of the platform’s security controls.
  • Secure Communications: Services support SSL/TLS, while 100% of intra-service communications use private IPs.
  • Application and Perimeter Protection: Web Application Firewall protection is implemented to provide an additional security layer for application traffic.
  • Access Security: MFA protects 100% of employee accounts, supporting strong authentication and access control practices.
  • Third-Party Security: Critical ICT suppliers are assessed through a third-party risk management process covering security certifications, risks, SLA and resilience commitments, and contingency plans.

Operational Context for Regulated Clients

RELIANOID maintains security practices designed to support customers operating in security-sensitive and regulated environments (like Finance, Healthcare, Government).

Our current security and compliance framework includes:

  • Network Security: Private IP usage for intra-service communication and SSL/TLS support.
  • Application Security: SSDLC enforcement, automated security scanning, WAF protection, and vulnerability monitoring.
  • Access Security: 100% MFA enforcement across employee accounts.
  • Resilience: Backup and restoration processes tested quarterly.
  • Third-Party Resilience: Critical suppliers are assessed for security, availability, SLA commitments, and contingency capabilities.

Vulnerability Management and Security Testing

RELIANOID continuously monitors and assesses vulnerabilities affecting its products and services.

The latest product vulnerability monitoring, dated 29 June 2026, reported 104 vulnerabilities fixed and 15 vulnerabilities remaining to fix.

Service and product pentesting and scanning conducted on the same date launched 1,007 tests. The assessment identified 16 high-risk findings, 12 medium-risk findings, 43 low-risk findings, and 89 informational findings. The report identifies 15 high-risk findings and one medium-risk finding as false positives, with remediation review scheduled for 1 October 2026.

Ongoing Improvements

RELIANOID continues to strengthen its network and security architecture through:

  • Centralized log correlation through a Security Information and Event Management (SIEM) platform, planned as a future improvement.
  • Data Loss Prevention (DLP) tooling and effectiveness, planned as a future improvement.
  • Continued vulnerability scanning, remediation, and security testing.
  • Continued strengthening of third-party risk management and supplier resilience.
  • Further development of incident response testing and lessons-learned processes.

Commitment to Our Clients

By aligning with ISO/IEC 27033 principles, RELIANOID continues to strengthen network security across its product and organizational environments. Our security framework combines secure communications, network protection, access controls, vulnerability management, application security, and resilience measures to support customers operating mission-critical and regulated environments.

Document Reviews

DateComment
10th July 2025Document creation
3rd September 2025Added network architecture models, multi-cloud alignment, DMZ patterns, perimeter & IPS integration, TLS/mTLS details, supplier security, and regulated client examples
30th June 2026Security and compliance review updated based on the RELIANOID Security Compliance Report 2026Q2

Contact and Assurance

We welcome requests for detailed security documentation, risk mapping matrices, or compliance disclosures.

Contact our Compliance & Security Team
Download Latest Security Report