Inherited via GCP

ISO 27001

Google Cloud Platform holds ISO 27001, ISO 27017, and ISO 27018 certifications covering the infrastructure Praktend runs on. Praktend inherits these controls by building exclusively on GCP. Praktend itself does not hold a direct ISO 27001 certificate and is not on a path to one in 2026.

Status Inherited via GCP GCP cert validity 2025-2028 Praktend direct cert Not on 2026 roadmap Last updated 2026-06-18
01  ·  What "inherited" means

Infrastructure controls already certified.

ISO 27001 is a certification for an organization's information security management system (ISMS). When a cloud provider like Google holds ISO 27001 for its data center infrastructure, compute, storage, and networking layers, workloads running on that infrastructure can assert they operate on a certified platform.

This is meaningfully different from Praktend holding its own direct certificate. A direct ISO 27001 certificate would require Praktend to scope its own ISMS, engage an accredited certification body, pass a Stage 1 and Stage 2 audit, and maintain the certification through annual surveillance audits. That process typically takes 12-18 months and several hundred thousand dollars. It is not on the 2026 plan.

What inherited coverage does provide: the physical and infrastructure layers under Praktend's application have already been audited by an accredited body. Praktend's application-layer controls are what a Praktend-direct audit would additionally cover.

02  ·  GCP certifications in scope

Three ISO standards. All three in force.

The following GCP certifications cover the Praktend production environment on GCP project praktend.

ISO 27001:2022

Information security management systems. Covers the core ISMS controls for Google's infrastructure and operations. Certificate held by Google LLC.

Inherited
ISO 27017:2015

Code of practice for information security controls based on ISO 27002 for cloud services. Cloud-specific guidance including virtual machine isolation and shared infrastructure responsibilities.

Inherited
ISO 27018:2019

Code of practice for protection of personally identifiable information (PII) in public clouds. Relevant to how GCP handles customer data it processes.

Inherited
Praktend App Layer

A direct Praktend ISO 27001 certificate would additionally cover application-layer controls, the Praktend ISMS, and organizational policies. This is not on the 2026 roadmap.

Not planned 2026
03  ·  What Praktend adds on top

Application-layer controls Praktend owns.

Inherited infrastructure certification does not cover Praktend's own application code, data access patterns, or organizational policies. These are the controls Praktend operates directly, independent of GCP's certification.

Data isolation

Per-company isolation enforced at the Firestore security rules layer. Cross-company reads raise a security violation at the middleware layer.

Live
Secrets management

All credentials and OAuth tokens live in GCP Secret Manager. Pre-commit hooks block any committed secret. No credentials in code, config, or environment files checked into the repo.

Live
Change management

Branch-protected main. All changes ship through CI with required review. Pre-commit hooks enforce PII scanner and secret detection on every commit.

Live
Access controls

Two-axis role model live. Quarterly access reviews and formal offboarding procedures in build. Required MFA policy in build.

Building
04  ·  The gap

What we cannot give you yet.

A direct Praktend ISO 27001 certificate

Praktend does not hold its own ISO 27001 certificate and is not pursuing one in 2026. If your procurement floor requires a directly-held, current ISO 27001 certificate from the software vendor (not just the infrastructure), we do not meet that requirement today. We will tell you that rather than stretch the "inherited" claim.

Questions about our ISO 27001 posture?

We will answer directly. No marketing language. Reply within twenty-four hours.

Send a question