Codexal Meet runs an information security management system modelled on ISO/IEC 27001:2022, with our controls mapped to Annex A. No external body has audited it, so this page says aligned, never certified.
Codexal Meet does not hold an ISO/IEC 27001 certificate. What exists is the management system a certificate attests to: a defined scope, a maintained risk register, an asset inventory, access reviews, an incident procedure and a documented Statement of Applicability against all 93 Annex A controls. If your procurement process requires a certificate, we will tell you we do not have one before you spend time on a questionnaire. If it allows evidence of an equivalent programme, everything below is available in writing.
Annex A gets the attention, but the clauses are what make it a system rather than a checklist.
The Codexal Meet platform: the web application, the signalling service, the database and the summary pipeline, plus the people and suppliers that operate them.
Security is owned by engineering leadership at Codexal, with a named individual accountable for the policy and for decisions that accept risk.
A risk register with likelihood, impact, an owner and a treatment plan, reviewed each quarter and whenever the architecture changes.
Written policies, security induction for new engineers, and documentation kept where the people who need it actually look.
Change control on production, security review before release, and supplier assessment before a new service is adopted.
Incidents and near misses produce corrective actions with owners, and the register is updated rather than the incident being closed quietly.
Thirty-seven controls in the 2022 revision. These are the ones a customer is most likely to ask about.
Most of this belongs to our hosting provider, and we say so rather than describing a data centre we do not operate.
The thirty-four controls where a meeting platform either does the work or does not. Most of these are verifiable from your own browser.
We send the control documentation to customers and to procurement teams evaluating us.