Certification scope expanded to cover the full product suite. SOC 2 Type II examination is underway.
UnderDefense Inc. has received ISO/IEC 27001:2022 certification, verified by an accredited external certification body. The certificate confirms that our information security management system meets the requirements of the international standard across the full scope of UnderDefense operations. This audit cycle is the first to include our product platforms alongside the service organization – an expansion that reflects where our business now operates and what our clients depend on.
The certificate is publicly available at our Trust Center: trust.underdefense.com.
What the Certification Covers
The ISO 27001 scope applies to UnderDefense Inc. and its two core platforms:
- UnderDefense Agentic AI SOC – the AI-powered security operations platform, providing continuous threat detection, investigation, and response
- UnderDefense MAXI Compliance AI – our GRC and compliance automation platform, which clients use to prepare for and pass their own certification audits

Organizations evaluating UnderDefense now have third-party confirmation that the platforms they depend on are held to the same security standard we help them achieve. The certification body reviewed our ISMS documentation suite, access controls, risk treatment, and operational controls – not a summary of them.
SOC 2 Type II Examination in Progress
Our SOC 2 Type II examination is currently underway, covering the AICPA Security Trust Services Criteria. A Type II examination evaluates whether controls operated effectively across an observation window, not just whether they were designed correctly at a point in time. The attestation report will be made available to clients and prospects through our Trust Center once the examination concludes.
ISO 27001 and SOC 2 address different buyer requirements. The certification satisfies European and enterprise procurement standards. The SOC 2 Type II attestation meets the expectations of US buyers and SaaS security review teams. Both frameworks share a significant control overlap, and our UnderDefense Compliance platform maps a single control set to both standards, so the work done for one carries into the other without duplication.
Both Audits Ran on Our Own Platform
The ISO 27001 certification and the SOC 2 Type II examination both ran through UnderDefense Compliance – the same platform our clients use. Policies, evidence collection, task tracking, and external auditor access all operated within the same system. Our certification body received a scoped, read-only Auditor role in the platform rather than a shared folder of exported files. From that role, the auditor could independently review controls, linked evidence, and policy documentation at their own pace, without requiring UnderDefense staff to screen-share through the fieldwork.
When the audit identified gaps in the platform itself, we found them first. Fixes shipped before any client encountered them.
Certification Path for Clients
UnderDefense clients pursuing their own ISO 27001 or SOC 2 certification can run the full audit lifecycle through UnderDefense Compliance and choose from four partner audit firms:
- Boulay Group
- Prescient Assurance
- Insight Assurance
- NOUV
Clients who already work with a certification body or CPA firm are welcome to bring their own auditor. The platform is auditor-agnostic. Any firm can be onboarded with a scoped Auditor role that grants read-only access to the audit scope – no evidence exports, no shared credentials, no screen-sharing sessions.
For organizations that need guidance on auditor selection, our team advises based on framework requirements, target market, geography, and budget. The right audit firm for a US-focused SaaS company is not automatically the right one for an EU enterprise supplier, and the difference matters for how the resulting certificate or report is received by buyers.
Trust Center
Our ISO 27001 certificate, security posture, and published security policies are available at trust.underdefense.com. When the SOC 2 Type II examination concludes, the attestation report will be published there as well.
Security review teams and procurement contacts can access certifications and documentation directly, without submitting questionnaires or waiting on requests. Every UnderDefense Compliance client can set up a Trust Center of their own – populated automatically from their compliance data, available on a custom domain – so their prospects can do the same.
About UnderDefense
UnderDefense is a cybersecurity company, with operations across the United States, Europe, and Ukraine. Its MAXI platform delivers Agentic AI SOC, Compliance AI automation, and CISO intelligence to enterprise clients, MSSP partners, and critical infrastructure operators across multiple continents. MAXI:BLACKHOLE.gov extends the platform’s full Agentic AI capability set to air-gapped and OT environments where conventional cloud-based security platforms cannot operate.
One platform. Every product. One place to manage it.
Media Contact: Nazar Tymoshyk, Founder & CEO – [email protected]




