Innovation & tips
Innovation & tips
A certificate alone does not make software secure. What counts is the work behind it: defined processes, clear responsibilities and careful handling of information. Since June 2026 that has been independently audited and confirmed at xappido.
Information security is hard to show. You cannot see it on the screen, and in everyday project work it usually only becomes noticeable when something is missing. So we are pleased that we can now provide evidence of it: an independent certification body has certified xappido to ISO/IEC 27001:2022, the internationally recognised standard for information security.
Being certified does not mean we bought a particular piece of software. The standard does not prescribe any technology. It requires a management system: transparent rules for how a company handles information, who is responsible for what, and how both are reviewed and developed further.
It begins with an unspectacular question: what information do we actually hold, and how much protection does each part of it need? Out of the answer come policies, responsibilities and a classification – because not everything is equally sensitive, and treating everything with the same rigour ends up treating nothing properly.
Then comes the risk assessment. Where can something go wrong, how likely is it, and how large would the impact be? Only once that is on the table can you decide which measures are really needed. That is exactly the order in which we worked: first the overview, then the rules, then the measures, and finally the review of how well they work.
A certificate always applies to a defined scope, and that scope is stated on the document. Ours covers the design, development, implementation, maintenance and operation of software solutions and the services associated with them.
That is deliberately the whole chain, not merely the administration in the background: from the first concept, through development in our offices in Sursee, to operating the solution that then runs every day.
If you would like to read it: the certificate is available as a PDF – registration number 226-06-018.I, valid until 17 June 2029. The document is in German.
The difference from a self-declaration is the independent body. It is not us confirming that our processes are sound, but a certification body that has examined them – one that comes back: the next surveillance audit is due in June 2027. A management system that exists only on paper does not survive that.
For you that means three things. You know how we handle your information, because it is governed by rules and does not depend on whoever happens to be working on the project. You can point to the evidence wherever information security has to be demonstrated, in a tender for example. And the security questions get asked early rather than shortly before go-live – because with us they are part of how we work.
We showed the road to certification from the beginning instead of presenting only the result. In a three-part video series, Sandra from our ICT and project management explains how we went about it: from the process map as the foundation, through policies and the classification of information, to the risk analysis. And then the moment the series builds up to – the certificate in hand.
Information security stays invisible as long as it works. Even so, it can now be proven.
Innovation & tips
Innovation & tips
Innovation & tips
A no-obligation intro call: in 30 minutes you will know what is possible.
Or directly: info@xappido.com
You will not find a phone number here, and that is deliberate: our lines belong to our customers, not to cold callers. Leave us your number and we will be glad to call you back.
“How we handle information follows set rules and is independently audited. Ask us about it and we will show you what that means for your task.”