Security certifications at Pilae: ISO 27001, NIST CSF and audit rights

Pilae is built to ISO 27001 controls and the NIST Cybersecurity Framework, hosted in ISO 27001-certified datacentres, and your contract gives you the right to audit us. Pilae SA holds no certification of its own today.

Talk to our teamRequest the security pack

Controls
Built to ISO 27001 controls and NIST CSF
Datacentres
ISO 27001-certified, in the region you choose
Pilae SA
No own certification today, ISO 27001 on the roadmap
Audit rights
In your contract

What we build to, and what we can prove

A certificate is one form of evidence. Until Pilae SA holds its own, we give you the controls, the evidence behind each one and the right to check them yourself.

ISO 27001 controls

Access control, change management, logging, backup, supplier management and incident response, designed against the ISO 27001 control set.

NIST Cybersecurity Framework

Our controls are mapped to the six functions of NIST CSF 2.0: govern, identify, protect, detect, respond and recover.

Certified datacentres

Pilae Cloud runs in datacentres whose operators hold ISO 27001 certification for them.

Security questionnaires answered

Your questionnaire, in your format, answered by an engineer with the evidence behind each control.

Evidence from the console

Audit logs, restore test records and change histories come straight from the console, not from a slide.

Right to audit

Your contract lets you or an auditor you appoint review our controls, with reasonable notice.

Where Pilae stands on certification

Pilae SA was founded in 2026 and does not hold its own certification today: no ISO 27001, no SOC 2, no ISAE 3402. An ISO 27001 certification of Pilae SA is on our roadmap. We say this plainly because your procurement team needs to know it.

What we give you instead is the controls, the evidence behind each one and the right to check them yourself.

Controls we build to

Pilae is built to ISO/IEC 27001 controls: access control, cryptography, operations security, change management, logging, backup, supplier management and incident response. The same controls are mapped to the six functions of the NIST Cybersecurity Framework 2.0. The technical and organisational measures annex of our data processing agreement lists each one. For how they work in practice, see security and backups and recovery.

Certifications of our providers

Pilae Cloud runs on dedicated machines in the region you choose, in datacentres that are ISO 27001-certified by their operators. That certification covers the buildings, power, cooling and physical access. It does not cover Pilae’s own operations, which is why the controls above and your audit rights matter. On your premises, your own datacentre certifications apply to the physical layer.

Audit rights and security reviews

Your contract gives you, or an independent auditor you appoint, the right to review our controls. We answer your security questionnaire before you sign, in your format, with evidence taken from the console: audit logs, change histories and restore test records.

For regulated sectors, see FINMA outsourcing and NIS2 and DORA. To start a review, talk to us.

How your security review runs

  1. Send your questionnaire

    Your own format or a standard one. We also send our controls list and data processing agreement.

  2. Answers with evidence

    An engineer answers each question and attaches the log, record or policy that shows the control.

  3. Review call

    Your security team questions ours directly. Open points are written down with an owner and a date.

  4. Audit clause agreed

    The scope, notice period and frequency of audits are written into your contract.

What your contract includes

Controls list
The technical and organisational measures in place, as an annex to your data processing agreement.
Audit rights
An audit by you or an independent auditor you appoint, with reasonable notice and an agreed scope.
Security questionnaire
Answered before you sign, and updated when you renew.
Provider certificates
Current ISO 27001 certificates of the datacentres hosting your machines, on request.
Changes to controls
Material changes to the measures notified to you in advance.

Questions

Is Pilae ISO 27001 certified?

No. Pilae SA does not hold its own certification today. Pilae is built to ISO 27001 controls, Pilae Cloud is hosted in ISO 27001-certified datacentres, and an ISO 27001 certification of Pilae SA is on our roadmap.

Does Pilae have a SOC 2 report?

No. Pilae SA does not hold a SOC 2 report or an ISAE 3402 report. We answer your security questionnaire with evidence for each control, and your contract gives you the right to audit us.

Which datacentre certifications apply to Pilae Cloud?

The datacentres that host Pilae Cloud are ISO 27001-certified. We provide the current certificates of the sites hosting your machines on request.

Can we audit Pilae?

Yes. Your contract gives you or an independent auditor you appoint the right to review our controls, with reasonable notice and an agreed scope.

Will you fill in our security questionnaire?

Yes. An engineer answers it in your format, attaches the evidence behind each control and joins a call with your security team if you want one.

Related

Send us your security questionnaire.

An engineer answers it with the controls in place and the evidence behind each one, before you sign.