ISO/IEC 27001
Aligned — certification in progress
Information Security Management System modelled on ISO/IEC 27001:2022 controls, with an internal audit programme and management review cycle.
This page is maintained by Dexra and summarises the certifications, partner accreditations and operational controls that underpin our delivery. For procurement packs, DPAs, penetration-test summaries or our latest SOC 2 status letter, request the trust pack.
Where a scheme is achieved, we say so. Where it's in-flight, we say that too — no "compliant with everything" theatre.
Aligned — certification in progress
Information Security Management System modelled on ISO/IEC 27001:2022 controls, with an internal audit programme and management review cycle.
Readiness programme underway
Security, Availability and Confidentiality Trust Services Criteria covered by documented controls; observation window in progress with an independent CPA firm.
Certified
Certified against the UK NCSC Cyber Essentials Plus scheme — annually re-tested by an accredited assessor.
Compliant
Registered UK data controller. DPA, SCCs and UK IDTA available. Data residency in UK and EU regions supported by default.
Designations across Digital & App Innovation and Data & AI on Azure.
Advanced tier with practices spanning Migration, DevOps and Machine Learning.
Access to L40S, H100/H200 and Blackwell platforms plus NVIDIA AI Enterprise licensing.
Certifications describe the frame. These are the controls Dexra operates every day across managed engagements.
SSO with enforced MFA, short-lived credentials, hardware-key admin access, and quarterly access reviews across every environment we operate.
TLS 1.3 in transit; AES-256 at rest across managed environments. Customer secrets held in customer-owned vaults; Dexra never brokers long-lived credentials.
Signed builds, SBOM generation, image and dependency scanning in CI, and CIS-benchmarked base images for every workload we ship.
Error-budget-driven change management, peer-reviewed IaC, immutable audit logs, and rehearsed rollback for every production deployment.
24/7 on-call rota, defined severity ladder, customer notification within contracted SLA, and post-incident reviews shared in writing.
Documented RTO/RPO per workload, tested restores, and geographically diverse infrastructure for managed services.
About the content on this page
Certifications, alignments and partner statuses listed here are maintained by Dexra and reflect our current programme. They are not independently verified by the hosting or design platform. Report a suspected security issue to security@dexra.cloud.
DPA, SCCs, information security policy summary, pen-test attestation and current SOC 2 status letter — sent on request under NDA.