Where Pilae stands on certification
Pilae SA was founded in 2026 and does not hold its own certification today: no ISO 27001, no SOC 2, no ISAE 3402. An ISO 27001 certification of Pilae SA is on our roadmap. We say this plainly because your procurement team needs to know it.
What we give you instead is the controls, the evidence behind each one and the right to check them yourself.
Controls we build to
Pilae is built to ISO/IEC 27001 controls: access control, cryptography, operations security, change management, logging, backup, supplier management and incident response. The same controls are mapped to the six functions of the NIST Cybersecurity Framework 2.0. The technical and organisational measures annex of our data processing agreement lists each one. For how they work in practice, see security and backups and recovery.
Certifications of our providers
Pilae Cloud runs on dedicated machines in the region you choose, in datacentres that are ISO 27001-certified by their operators. That certification covers the buildings, power, cooling and physical access. It does not cover Pilaeās own operations, which is why the controls above and your audit rights matter. On your premises, your own datacentre certifications apply to the physical layer.
Audit rights and security reviews
Your contract gives you, or an independent auditor you appoint, the right to review our controls. We answer your security questionnaire before you sign, in your format, with evidence taken from the console: audit logs, change histories and restore test records.
For regulated sectors, see FINMA outsourcing and NIS2 and DORA. To start a review, talk to us.