01In plain English
ISO 27001 is an international standard for running an information security programme. A company is certified when an accredited body audits it and confirms its security processes meet the standard. It is renewed on a regular cycle, with checks in between.
02Why it matters when you are choosing
It does the same job as SOC 2 for buyers outside the US, and European and Asian companies often ask for it first. Holding both usually means a vendor has a mature security team.
03What to check
Ask for the certificate and check the scope: it should cover the product you are buying, not only one office or a different part of the business.
04The tools
37 of the 79 tools we checked hold ISO 27001. Each one is checked against the vendor's own pages. A tool missing from this list may not have been checked yet, which is not the same as a no.


Fin


Intercom


Workato


Dify


GitHub

