Security Center
1. Overview
Allcontrols OÜ is a certification body and information security services company. We provide certification of management systems, security audits, penetration testing, trainings, and related professional services. Certification activities are performed in accordance with ISO/IEC 17021-1:2015 and are organizationally separated from all non-certification services.
Our security and governance framework is designed to support the confidentiality, integrity, and availability of client data, audit evidence, security testing results, compliance documentation, internal business information, and other sensitive information entrusted to Allcontrols.
2. Certification Body Information
Allcontrols provides third-party certification of management systems in accordance with ISO/IEC 17021-1:2015 within the following schemes:
- ISO/IEC 27001:2022 — Information Security Management Systems (certification process);
- ISO/IEC 27701:2025 — Privacy Information Management Systems (certification process.
Certification services are delivered remotely and on-site in the EU/EEA and internationally. Information describing our audit processes; the processes for granting, refusing, maintaining, renewing, suspending, restoring, or withdrawing certification and for expanding or reducing the scope of certification; and the rules for the use of the certificate and certification mark is published on the certification pages linked above and is also available upon request at [email protected].
3. Impartiality
The top management of Allcontrols is committed to impartiality in its management system certification activities. Allcontrols understands the importance of impartiality, identifies and analyses risks to impartiality on an ongoing basis — including risks arising from its other services, relationships, and personnel — manages conflicts of interest, and ensures the objectivity of its certification activities through a dedicated oversight mechanism.
- Certification activities are organizationally and operationally separated from consulting, implementation, penetration testing, training, and software development services.
- Allcontrols does not provide management system consultancy or internal audits to organizations it certifies, and does not certify management systems on which it, or a related body, has provided consultancy.
- Audit team members and persons making certification decisions declare conflicts of interest and are not assigned to clients for whom they have provided consultancy or have had a relationship that threatens impartiality.
- Certification decisions are made by competent persons who did not participate in the audit.
- Certification is not conditional on the purchase of any other Allcontrols service, and no commercial, financial, or other pressure is permitted to compromise impartiality.
4. Complaints & Appeals
Any organization or interested party may submit a complaint about Allcontrols’ certification activities or a certified client, or an appeal against a certification decision, by contacting [email protected]. The process is as follows:
- Acknowledgement: Receipt of each complaint or appeal is acknowledged, and the submitter is provided with progress reports and the outcome.
- Review: The matter is investigated, and the resulting decision is made or reviewed and approved, by personnel not involved in the subject of the complaint or appeal.
- Complaints about certified clients: These are examined with regard to the effectiveness of the certified management system and are referred to the certified organization where appropriate.
- Confidentiality & non-discrimination: The identity of complainants and appellants is treated confidentially, and submitting a complaint or an appeal does not result in any discriminatory action against the submitter.
5. Certificate Verification
To confirm the validity and status of a certificate issued by Allcontrols (certified organization, applicable standard, scope, and locations), please contact [email protected]. Information on granted, suspended, or withdrawn certifications is provided upon request.
6. Use of Certificate & Certification Mark
- The certificate and certification mark may be used only in relation to the certified scope and locations, and in accordance with Allcontrols’ rules for the use of the mark, which are provided to certified clients and available upon request.
- The certification mark must not be applied to products or product packaging, or used in any way that may be interpreted as denoting product conformity.
- Certification must not be presented in a misleading manner; upon suspension or withdrawal, all use of the certificate, the mark, and references to certification must cease.
- Suspected misuse of a certificate or certification mark may be reported to [email protected].
7. Our Certifications
Allcontrols itself maintains independently certified governance, security, and quality processes to support reliable service delivery and responsible handling of client information:
- ISO/IEC 27001:2022 — Information Security Management System. Our information security controls cover access management, information classification, secure handling, risk management, incident response, supplier management, and continual improvement.
- ISO 9001:2015 — Quality Management System. Our quality management processes support consistent service delivery, documented procedures, management review, corrective actions, and continual improvement.
Certificates may be provided to clients, partners, and other authorized parties upon request or under NDA where appropriate.
8. Security Governance
Allcontrols maintains documented policies, procedures, and internal controls to manage information security, data protection, confidentiality, ethical conduct, and professional independence. Our governance approach includes:
- Documented information security and data protection policies;
- Defined responsibilities for secure handling of client and internal information;
- Access control based on business need-to-know principles;
- Confidentiality obligations for personnel and contractors;
- Security awareness and data protection training;
- Incident reporting and response procedures;
- Periodic review and continual improvement of internal controls.
9. Data Protection
Allcontrols processes personal data in accordance with applicable data protection laws, including the GDPR. Depending on the context, Allcontrols may act either as a data processor on behalf of a client or as an independent data controller for activities such as website operation, recruitment, and sales or CRM activities. We apply appropriate technical and organizational measures to protect personal data and other sensitive information, including:
- Access controls and authentication;
- Confidentiality agreements and personnel obligations;
- Secure storage and communication practices;
- Logging and monitoring where applicable;
- Backup and recovery controls;
- System hardening and patch management;
- Incident response and escalation procedures;
- Data minimization and privacy by design principles.
10. Confidentiality
Allcontrols personnel, committee members, and contractors are bound by enforceable confidentiality obligations covering all information obtained or created during certification and other engagements. This includes, but is not limited to:
- Client data and documentation;
- Audit reports, audit evidence, and certification records;
- Security testing results and vulnerability findings;
- Risk analyses and remediation information;
- Source code, system configurations, and architectural information;
- Internal methodologies, procedures, and business information.
Access to confidential information is limited to authorized personnel with a legitimate business need. Information about a client is not disclosed to a third party without the written consent of the client, except where disclosure is required by law; in such cases, the client is notified of the information provided unless prohibited by law. Unauthorized disclosure, misuse, or mishandling of confidential information is prohibited.
11. Professional Conduct
Allcontrols performs certification, audit, and security testing services in accordance with documented scopes of work, applicable standards, contractual obligations, and professional ethics. Personnel involved in client engagements are required to:
- Perform services objectively, impartially, and professionally;
- Maintain and demonstrate the competence required for their assigned activities;
- Disclose relevant findings truthfully and without misrepresentation;
- Avoid misleading statements about certification status, compliance, or risk levels;
- Protect client information and engagement records;
- Declare conflicts of interest and maintain independence;
- Escalate ethical, security, or compliance concerns when identified.
12. Public Policies
The following documents describe Allcontrols’ commitments to impartiality, privacy, information security, ethical conduct, anti-bribery, confidentiality, and responsible business practices.
| Policy / Document | Description | Availability |
|---|---|---|
| Impartiality Statement | Top management commitment to impartiality in certification activities, management of conflicts of interest, and objectivity of certification. | Published on this page (Section 3) |
| Certification Process Descriptions | Audit processes and the processes for granting, refusing, maintaining, renewing, suspending, restoring, and withdrawing certification, and for expanding or reducing its scope. | Published on the certification pages |
| Complaints & Appeals Procedure | Process for handling requests for information, complaints, and appeals related to certification activities. | Published on this page (Section 4) |
| Rules for Use of Certificate & Mark | Requirements for the use of Allcontrols’ name, certificate, and certification mark by certified organizations. | Provided to certified clients; available upon request |
| Code of Conduct | Defines ethical principles, professional standards, confidentiality obligations, compliance expectations, and reporting responsibilities. | Available upon request |
| Ethics Policy | Confirms Allcontrols’ commitment to integrity, transparency, fairness, accountability, and responsible business conduct. | Available upon request |
| Anti-Bribery and Corruption Policy | Prohibits bribery, facilitation payments, kickbacks, improper gifts, and other corrupt practices in business dealings. | Available upon request |
| Privacy Policy | Explains how Allcontrols collects, uses, protects, and manages personal data in connection with its services, website, recruitment, and business activities. | Published |
| Platform Privacy Policy | Describes privacy practices related to users of Allcontrols’ platform and related platform services. | Available upon request |
Copies of public policies and governance documents may be provided to clients, partners, and other authorized parties upon request. Additional internal policies may be shared under NDA where appropriate.
13. Security Requests & Contacts
Clients, partners, and authorized third parties may request additional information about Allcontrols’ certification, security, compliance, and governance practices. Depending on the nature of the request, Allcontrols may provide:
- Information on certification processes and the status of issued certificates;
- ISO/IEC 27001 and ISO 9001 certificate information for Allcontrols itself;
- Public policies and governance documents;
- Security questionnaire responses;
- Information about technical and organizational controls;
- Additional internal policies under NDA where appropriate.
For certification, security, compliance, or certificate requests: [email protected].
For complaints and appeals regarding certification activities: [email protected].
For privacy or data protection questions: [email protected].