
Certification
ISO 27001:2022 Information Security Management System certification, obtained in June 2026.
A copy of the certificate is available on request.
Security work we have actually done
- VANS vulnerability reporting and high-risk software updates (National Institute of Cyber Security)
- Host vulnerability scanning and remediation appeals
- National Information and Communication Security Taskforce cyber attack and defence drills
- Business continuity plan (BCP) exercises
- GCB government configuration baseline implementation
- Endpoint threat detection deployment
- Annual penetration testing
- ISMS records and audit documentation upkeep
All of the above were carried out on public-sector and Taiwan Broadcasting System projects we delivered.
Common procurement security requirements we can meet
| Requirement | How we meet it |
|---|---|
| Data residency region | Can be pinned to an Asia region, or any cloud region you specify |
| Data localisation and cross-border transfer | We can contract for no cross-border transfer; AI applications handling private data can run inside your own environment |
| Log retention period | Configurable; public-sector projects commonly require 6 months or more |
| Restrictions on project personnel | We can provide a declaration of personnel nationality |
| Origin of ICT equipment | We can provide a declaration of equipment brand and origin |
| Vulnerability scanning and penetration testing | Can be included in the project scope or in an annual maintenance contract |
| Personal data protection | Collection, processing and use follow the Personal Data Protection Act; we can sign a personal data protection agreement |
How we work internally
Project isolation
Client data and source code are isolated per project
Key management
Keys and certificates are managed centrally, never committed to source code
Dependencies
Dependency vulnerability checks before every release
Transport & consent
HTTPS across the whole site, with tracking consent managed through Google Consent Mode v2
The purpose of collection, the retention period and the deletion process for personal data are set out in the Privacy Policy.
If you are preparing a tender
Tell us your deadline and we will prepare the documents you need from us: ISO certificate, company registration, proof of past projects, staff CVs and security declarations.
Tell us your deadline