Insights

ClearPoint is now ISO/IEC 27001 Certified

Written by ClearPoint | Sep 30, 2026, 4:10:11 AM

By Paul Scott, Chief Operating Officer

 

ClearPoint has achieved ISO/IEC 27001 certification, the international standard for information security management systems (ISMS). It gives independent recognition to security practices we've followed for 19 years.

An independent certification body confirmed our certification in August following a two stage audit. It covers our whole business across New Zealand, Australia and the United Kingdom, giving us one consistent security framework as we expand internationally and grow our enterprise and public sector work.

Our new ClearPoint Trust Centre at https://trust.clearpoint.digital/ also brings our certification and security practices together in one place providing full transparency for clients and prospects.

 

A formal step for a long-standing discipline

Security is built into every engagement we run, from how we access client systems to how we handle client data. Certification formalises that approach against a recognised international standard.

Auditors reviewed and verified how we manage information security risk, including how we control access to client information and systems. This milestone reflects the work of people right across our business.

 

Security has always been part of how we work, because our clients trust us with systems their businesses depend on. ISO/IEC 27001 gives their security teams independent evidence of that, so we can start delivering for them sooner.

Paul Scott - Chief Operating Officer at ClearPoint

 

Allows clients to get started faster


Bringing a new technology partner on board usually means working through the client's own security and compliance processes before project work can start. For the engineering and product leaders keen to get going, that step can hold up the start of a project.

Certification gives those security teams a clear, audited baseline from the first conversation.

 

On a recent new client onboarding, we met with the client's security team once and had the green light within two days, with no detailed security questionnaire needed. Before certification, that same step would typically have taken a few weeks.

Paul Scott - Chief Operating Officer at ClearPoint

 

That leaves client teams free to focus on the products and features being built with us, knowing our security processes and controls are already built into how we operate.


Designed to fit with how you work


We work across corporate and public sector organisations, each with its own security policies and processes. We designed our ISMS to fit alongside client policies.

Where a client already has established security practices or regulatory requirements, our processes work within them. For clients still building that capability, we bring the security expertise and audited controls into the engagement from the start.

 

Why it matters for the AI-driven future


Certification carries extra weight as we lead with Agentic AI services. These services often need access to sensitive client data and systems, and clients rightly want to understand how that access is governed.

ISO/IEC 27001 shows clients that we manage those risks within a recognised framework.

 

Built to keep improving


ISO/IEC 27001 requires ongoing monitoring and annual surveillance audits, so we’ll keep testing and strengthening our security practices over time. The standards we set during certification are now business as usual across every team.

Certification is one part of how we look after the systems and data our clients trust us with.

If you'd like to talk about how we protect your systems and data, or about what you're planning next, we'd love to hear from you.