Aug 25, 2026

UnderDefense Is Now ISO 27001 Certified. We Ran the Entire Audit on Our Own Platform

Every GRC vendor tells you compliance can be simple. Very few of them go through a certification audit on their own product and then publish the certificate.

We did. UnderDefense Inc. has earned ISO/IEC 27001:2022 certification, and our SOC 2 Type II examination is in its final stage. Both audits ran end to end inside UnderDefense MAXI Compliance AI, the same platform our clients use. Same policy engine, same evidence vault, same task board, same auditor role. No parallel spreadsheet, no shadow SharePoint folder, no internal exception.

In this article:

  • What exactly we certified, and how MAXI MDR and Compliance AI fit into the audit scope
  • How a full audit lifecycle (policies, evidence, AI-assisted review, tasks, auditor access) runs inside one platform
  • How we gave our external auditor a read-only, least-privilege role instead of a shared drive full of screenshots
  • How you can run the same process with one of our four partner audit firms, or with your own auditor

What is ISO/IEC 27001? ISO/IEC 27001 is the international standard for an information security management system (ISMS). It specifies requirements for establishing, implementing, maintaining, and continuously improving an ISMS, including risk assessment and treatment. Certification is issued by an accredited external body following a Stage 1 documentation audit and Stage 2 fieldwork audit, with annual surveillance audits thereafter.

See how UnderDefense MAXI Compliance AI cuts audit prep time.

What Does UnderDefense’s ISO 27001 Certification Cover?

The certification covers UnderDefense Inc. and the products our clients depend on:

  • UnderDefense MAXI MDR – 24/7 managed detection and response
  • UnderDefense MAXI Compliance AI – our GRC and compliance automation platform

In other words, the platform that manages your compliance is itself certified against the standard it helps you meet.

ISO/IEC 27001:2022 – certified.

SOC 2 Type II – final stage of the examination, covering Security Trust Services Criteria.

Why both? Our clients divide across two procurement realities. European and enterprise procurement teams require ISO 27001. US buyers, and specifically SaaS procurement and security review teams, require a SOC 2 report. Maintaining both from a single control set is exactly the problem the Compliance AI was built to solve. We now have the receipts.

Dual certification dashboard

Why Did We Run Our Own Certification Audit on Our Own Platform?

There is a specific kind of credibility you only earn by being on the receiving end of an audit.

We already knew the theory: centralize evidence, map controls once, keep everything continuously audit-ready. Running our own ISO 27001 certification and SOC 2 Type II examination through the Compliance AI meant our ISMS Committee, engineering teams, HR and IT owners, and an external audit firm all worked in the same system at the same time.

Everything the auditor asked for existed in one place, attached to the control it proved, with an owner and a timestamp. And where the platform could have been better, we felt it first, and shipped fixes before our clients ever hit them.

How Does a Full Audit Lifecycle Run Inside the Platform?

The Full Policy Lifecycle: Creation to Acknowledgement

Our entire ISMS documentation suite was authored, reviewed, approved, and published inside the Compliance AI: Master Information Security Policy, Access Management, Information Classification, BCDR Plan and Policy, Internal Audit, Software Management, BYOD, System Documentation, and the rest.

Each policy started from a framework-aligned template, went through review and approval with a named owner, and was mapped to the controls it satisfies.

MAXI Compliance dashboard

Evidence: Collected, Linked, and AI-Reviewed

Evidence is where most audits go sideways. Screenshots in Slack threads. Exports on someone’s laptop. A configuration change nobody documented.

In the Compliance AI, every piece of evidence attaches directly to the task it covers. CISO Copilot checks submitted evidence automatically before a human reviewer looks at it: is it the right artifact type, is it within the observation window, does it actually address the control, is anything missing or expired?

That single step removed most of the back-and-forth that normally eats audit calendars. The platform flagged weak evidence in week one. The auditor did not reject it in week six.

AI evidence preview flow

Tasks and Real Ownership

The audit ran as a task board. Every gap became a task with a description, an assignee, a due date, and a status. Every completed task moved the compliance percentage, visibly, in real time, for everyone involved.

That mattered more than it sounds. When a DevOps engineer can see that their one task moves the company’s ISO 27001 readiness, compliance stops being someone else’s paperwork.

The Auditor Role: Least Privilege, By Design

We did not send our auditor a zip file. We did not create a shared drive with broad permissions and hope for the best. We gave our external auditor a native Auditor role in the Compliance AI, governed by role-based access control that grants view-only access limited to exactly the scope required.

The auditor could open controls, read policies, inspect evidence, and follow the mapping from requirement to artifact, independently, at their own pace, without an UnderDefense employee screen-sharing for hours at a time. They could not modify, delete, or reach anything outside the audit scope.

The result: faster fieldwork for the auditor, zero over-provisioning on our side, and a clean access trail that is itself audit evidence.

How Did the Certification Process Actually Go?

  • Scoping and gap analysis. We defined the scope (UnderDefense Inc., MAXI MDR, Compliance AI), loaded the ISO 27001 and SOC 2 control sets in the platform, and ran a gap analysis against what already existed.
  • Risk assessment and Statement of Applicability. Risk assessment and treatment plan built in the platform, with SoA completed and documented justifications for both inclusion and exclusion of controls.
  • Internal working calls with the team. Regular ISMS Committee syncs, plus focused sessions with control owners across engineering, IT, and HR. Every call ended with tasks in the platform, not notes in a doc.
  • Calls with the auditor. Kick-off, scope confirmation, walkthroughs, and status checkpoints, with the auditor already inside the platform and looking at the same evidence we were.
  • Evidence collection and AI pre-review. Continuous throughout the process, with weak or stale artifacts flagged early.
  • Fieldwork and certification. The auditor worked through their Auditor role, requested clarifications where needed, and issued the ISO 27001 certificate. SOC 2 Type II is in the final stage now.

Where Can You Verify Our Security Posture?

Our ISO 27001 certificate, our policies, and our security posture – including the SOC 2 Type II attestation when the report is issued – are all published on the UnderDefense Trust Center at trust.underdefense.com.

That Trust Center is a Compliance AI feature, hosted on the same platform, fed by the same control and document data, and it updates when our compliance status updates.

Trust Center

Every Compliance AI customer can stand up their own Trust Center the same way, with published certificates and policies, and self-service access for prospects and security reviewers. If your sales cycle currently stalls every time a prospect sends a 200-row security questionnaire, this is the fix: point them at your Trust Center and let them self-serve.

Which Audit Partners Can You Work With?

Certification is not something you buy, but the path to it does not have to be something you invent from scratch.

UnderDefense clients can run their audit with one of four partner audit firms:

  • Boulay Group
  • Prescient Assurance
  • Insight Assurance
  • NOUV

You can also bring your own auditor. If you already have a CPA firm or certification body you trust, the Compliance AI works with them exactly the way it worked with ours: give them the Auditor role, scoped and read-only, and let them work.

Not sure which auditor fits? Our team advises on selection based on your framework, your buyers, your geography, and your budget. The right auditor for a US-focused SaaS company is not automatically the right one for an EU enterprise supplier.

How Do You Run Your ISO 27001 or SOC 2 Audit End to End?

Most compliance tools help you prepare and then hand you off. Most consultancies help you prepare and then bill you for the handoff.

UnderDefense covers the full arc:

  • Prepare – framework templates, cross-framework control mapping, policy lifecycle, task management, continuous evidence collection, AI-assisted evidence review, real-time readiness dashboard
  • Get expert help – our security consulting and vCISO specialists work alongside your team: gap assessments, risk assessment, control implementation, cloud hardening, policy authoring, audit readiness reviews
  • Get audited – run the audit in the platform with a partner auditor or your own, using a scoped read-only Auditor role
  • Prove it, continuously – publish to your Trust Center and stay audit-ready between cycles

Prepare for the audit, pass the audit, and prove it to your customers. In one place. That is the whole idea. And now we have run it on ourselves.

Ready to Get Certified?

If your team is working toward an ISO 27001 certification, a SOC 2 Type II, or both at once, the fastest way to understand what this looks like is to see it.

Schedule a demo and we will walk you through the exact workflow we used for our own certification, including the auditor role, the evidence vault, and the Trust Center.

Visit the UnderDefense Trust Center to see our ISO 27001 certificate and security posture.

Subscribe to the UnderDefense Vulnerability Intelligence Newsletter for weekly analysis of new vulnerabilities, exploited attack vectors, and practical remediation guidance.

UnderDefense MAXI Compliance AI: One platform, every framework, zero spreadsheets.

1. What does UnderDefense's ISO 27001 certification cover?

The certification covers UnderDefense Inc. and its core products: UnderDefense MDR and UnderDefense MAXI Compliance AI. It confirms that our information security management system meets the requirements of ISO/IEC 27001:2022, verified by an accredited external certification body. The certificate is published on our public Trust Center.

2. Is UnderDefense SOC 2 compliant?

Our SOC 2 Type II examination is in its final stage. Unlike ISO 27001, SOC 2 is an attestation performed by a CPA firm, and a Type II report evaluates whether controls operated effectively across an observation window. The report will be made available to customers and prospects through the Trust Center once issued.

3. What is the difference between ISO 27001 and SOC 2 Type II?

ISO 27001 is an international standard for an ISMS, certified by an accredited body on a multi-year cycle with annual surveillance audits. SOC 2 is a US attestation framework built on the AICPA Trust Services Criteria, reported on by a CPA firm. Type I assesses control design at a point in time; Type II assesses operating effectiveness over a period. UnderDefense MAXI Compliance AI maps a single control set to both so the work is done once.

4. Can our external auditor access UnderDefense MAXI Compliance AI directly?

Yes. UnderDefense MAXI Compliance AI includes a dedicated Auditor role governed by role-based access control. It grants view-only access limited to the audit scope, so an auditor can independently review controls, policies, and linked evidence without being able to modify anything or access data outside that scope. We used exactly this role for our own audits.

5. Which audit firms can we work with?

UnderDefense works with four partner audit firms and can advise on which fits your framework, target market, and budget. You are also free to bring your own auditor or certification body. The platform is auditor-agnostic, and any firm can be onboarded with a scoped Auditor role.

6. What is a Trust Center, and can we publish our own?

A Trust Center is a public page where you publish your certifications, security posture, and policies so prospects and security reviewers can self-serve rather than sending questionnaires. UnderDefense’s own Trust Center runs on UnderDefense MAXI Compliance AI, and any customer can set one up, including on a custom domain, populated automatically from their compliance data.

7. Do we get human help, or just software?

Both. UnderDefense MAXI Compliance AI automates the platform work: templates, control mapping, evidence collection and AI-assisted review, task tracking, reporting. Alongside it, UnderDefense security consulting and vCISO specialists assist with gap assessments, risk assessment, control implementation, policy authoring, and audit readiness. You can use the platform on its own or with our team embedded in the project.

8. How long does it take to get ISO 27001 certified?

Timelines depend on starting maturity, scope, and how quickly control owners can implement and evidence what is missing. What consistently shortens the process is eliminating the two biggest time sinks: hunting for evidence and reworking rejected evidence. Continuous collection with automated pre-review, cross-framework mapping, and direct auditor access address both.

Ready to protect your company with Underdefense MDR?

Related Articles

See All Blog Posts