Security & Compliance

Trust, audited.

bizSupply is built and operated by Infosistema, certified to ISO/IEC 27001 (information security) and ISO 9001 (quality management). Below: the certifications themselves, the security pillars that back them, and how to reach us if you need certificate copies or a security review for procurement.

Independent verification

Certifications

Audited annually by independent certification bodies. Coverage extends across all Infosistema products and services. Certificate copies and full scope statements available on request — email privacy@infosistema.com.

ISO/IEC 27001 mark of trust

ISO/IEC 27001

Information Security Management

Body
BSI
Audited
Annually
Coverage
Design, development, operation, and support of bizSupply and all Infosistema SaaS products.
Extensions
ISO/IEC 27017 (cloud-security controls), ISO/IEC 27018 (protection of personal data in cloud).
ISO 9001 mark of trust

ISO 9001

Quality Management

Body
IQNET
Audited
Annually
Coverage
Design, development, operation, and support of all Infosistema products and services, including bizSupply.
Additional frameworks
GDPR·Data protection (EU)
CCPA·Data protection (California)
OWASP·Application security
SOC 2·Coming soon

How we protect your data

The certifications above don't tell you what we actually do. These are the operating controls that back them.

Encryption everywhere

TLS 1.2+ in transit, AES-256 at rest. Data and credentials are never stored in plaintext.

Least-privilege access

Role-based access control with per-workspace scoping. No standing admin credentials; production access is time-bound and audited.

Customer-data isolation

Contract data, vendor records, and analytics live in tenant-scoped storage. We do not use Customer Data to train models or for any purpose outside service delivery.

Audit-ready logging

Every privileged action and data export is logged with actor, timestamp, and outcome. Logs are retained per the data-retention policy in the Privacy Policy.

Region-pinned infrastructure

Hosted on Google Cloud Platform with EU and US regions. EU customers stay in europe-west1; US customers stay in us-central1.

Incident response

Documented runbooks for credential rotation, history-scrub, and breach notification (72 hours per GDPR). Both production servers are monitored continuously.

Need a certificate copy or a security review?

Procurement teams and security reviewers can request ISO certificate copies, scope statements, and our standard Data Processing Agreement (DPA). For ongoing platform privacy questions see the Privacy Policy.