ISO/IEC 27001 — current attestation · Valid through Q4 2026

Framework · ISO 27001

ISO 27001 — Annex A controls mapped.

ISO/IEC 27001 covers the information security management system — Annex A controls, the statement of applicability, and the surveillance audit trail. This page walks the framework, the controls in scope across asset management, access control, incident response, encryption and supplier relationships, and how to request the latest report.

The Helmsway ISMS covers the people, processes and systems that produce the platform — engineering, security and AI ops under a single named leadership chain, the production platform and its data stores under a single asset register, and every external processor under a single supplier onboarding flow. ISO/IEC 27001 is the framework that audits that ISMS — the same Annex A controls the engineering org runs against, with named owners, a statement of applicability and a surveillance audit cycle. It tells a security reviewer that information security isn't a poster on a wall; it is the controls the platform runs against, every quarter, with one named owner per row.

Internal audit + management review

Audit cadence · ISMS

Annual surveillance audit by a Big-Four-affiliated certification body, written against the ISMS scope named on the front of the SoA. Inside that window, an internal audit fires every six months against the same Annex A rows and a management review at every quarterly ISMS cycle — minute-by-minute diff against the surveillance evidence ledger the external auditor pulls next.

Statement of applicability

Every Annex A family, declared.

The SoA booklet names every Annex A control family — applicable, not-applicable or justified-exclusion — with a one-line rationale per row. The auditor diffs the named rows against the surveillance evidence ledger; the prose is the framing, the rows are the test.

Data in scope · ISMS asset register

Assets + ingest surfaces the ISMS covers.

The Helmsway ISMS asset register names every data store and ingest surface that holds merchant or model data — with a classifier, a named owner and a re-attestation cadence. The operational ingest point the ISMS is written against is the Shopify connector, with every pickup journalised to the append-only audit ledger. The /integrations/shopify landing walks the connector data shape end to end so a reviewer can read the ingest surface in the same assessment pass.

Risk treatment plan

How each named ISMS risk is treated.

Every named ISMS risk carries a treatment choice, a residual tier and the next review window. The risk register is the same booklet the surveillance audit diffs at the next window — four named rows below, written against the ISMS scope the SoA booklet declares.

  • Privileged-path misuse

    JIT admin + two-person approval + append-only ledger

    Residual: Low

  • External-processor data exposure

    Supplier onboarding flow + DPA + monthly vendor-risk review

    Residual: Low

  • Key custody single point of failure

    Key custody split between security and platform teams + rotation cadence

    Residual: Low

  • Incident-response drift

    Named on-call + severity ladder + customer-comms tree + post-incident review

    Residual: Medium

Latest report

Request the latest ISO 27001 report.

The full ISO/IEC 27001 statement of applicability, the surveillance audit trail, the Annex A risk treatment plan and the latest audit window ship on a mutual NDA under one business day. Send a note and the security contact comes back to you directly.

Replies land with the security contact, not a sales sequence.

See it on your store

See it on your store →

Skip the questionnaire — book a Scale-tier demo and watch the helm pull a lever on your Shopify store.

See it on your store →

ISO/IEC 27001 covers the information security management system — Annex A controls, the statement of applicability, and the surveillance audit trail. This page walks the framework, the controls in scope across asset management, access control, incident response, encryption and supplier relationships, and how to request the latest report.

← Back to trust center