Google Cloud Platform holds ISO 27001, ISO 27017, and ISO 27018 certifications covering the infrastructure Praktend runs on. Praktend inherits these controls by building exclusively on GCP. Praktend itself does not hold a direct ISO 27001 certificate and is not on a path to one in 2026.
ISO 27001 is a certification for an organization's information security management system (ISMS). When a cloud provider like Google holds ISO 27001 for its data center infrastructure, compute, storage, and networking layers, workloads running on that infrastructure can assert they operate on a certified platform.
This is meaningfully different from Praktend holding its own direct certificate. A direct ISO 27001 certificate would require Praktend to scope its own ISMS, engage an accredited certification body, pass a Stage 1 and Stage 2 audit, and maintain the certification through annual surveillance audits. That process typically takes 12-18 months and several hundred thousand dollars. It is not on the 2026 plan.
What inherited coverage does provide: the physical and infrastructure layers under Praktend's application have already been audited by an accredited body. Praktend's application-layer controls are what a Praktend-direct audit would additionally cover.
The following GCP certifications cover the Praktend production environment on GCP project praktend.
Information security management systems. Covers the core ISMS controls for Google's infrastructure and operations. Certificate held by Google LLC.
InheritedCode of practice for information security controls based on ISO 27002 for cloud services. Cloud-specific guidance including virtual machine isolation and shared infrastructure responsibilities.
InheritedCode of practice for protection of personally identifiable information (PII) in public clouds. Relevant to how GCP handles customer data it processes.
InheritedA direct Praktend ISO 27001 certificate would additionally cover application-layer controls, the Praktend ISMS, and organizational policies. This is not on the 2026 roadmap.
Not planned 2026Inherited infrastructure certification does not cover Praktend's own application code, data access patterns, or organizational policies. These are the controls Praktend operates directly, independent of GCP's certification.
Per-company isolation enforced at the Firestore security rules layer. Cross-company reads raise a security violation at the middleware layer.
LiveAll credentials and OAuth tokens live in GCP Secret Manager. Pre-commit hooks block any committed secret. No credentials in code, config, or environment files checked into the repo.
LiveBranch-protected main. All changes ship through CI with required review. Pre-commit hooks enforce PII scanner and secret detection on every commit.
LiveTwo-axis role model live. Quarterly access reviews and formal offboarding procedures in build. Required MFA policy in build.
BuildingPraktend does not hold its own ISO 27001 certificate and is not pursuing one in 2026. If your procurement floor requires a directly-held, current ISO 27001 certificate from the software vendor (not just the infrastructure), we do not meet that requirement today. We will tell you that rather than stretch the "inherited" claim.
We will answer directly. No marketing language. Reply within twenty-four hours.
Send a question →