Framework · ISO 27001
ISO 27001 — Annex A controls mapped.
ISO/IEC 27001 covers the information security management system — Annex A controls, the statement of applicability, and the surveillance audit trail. This page walks the framework, the controls in scope across asset management, access control, incident response, encryption and supplier relationships, and how to request the latest report.
The Helmsway ISMS covers the people, processes and systems that produce the platform — engineering, security and AI ops under a single named leadership chain, the production platform and its data stores under a single asset register, and every external processor under a single supplier onboarding flow. ISO/IEC 27001 is the framework that audits that ISMS — the same Annex A controls the engineering org runs against, with named owners, a statement of applicability and a surveillance audit cycle. It tells a security reviewer that information security isn't a poster on a wall; it is the controls the platform runs against, every quarter, with one named owner per row.
Internal audit + management review
Audit cadence · ISMS
Annual surveillance audit by a Big-Four-affiliated certification body, written against the ISMS scope named on the front of the SoA. Inside that window, an internal audit fires every six months against the same Annex A rows and a management review at every quarterly ISMS cycle — minute-by-minute diff against the surveillance evidence ledger the external auditor pulls next.
Statement of applicability
Every Annex A family, declared.
The SoA booklet names every Annex A control family — applicable, not-applicable or justified-exclusion — with a one-line rationale per row. The auditor diffs the named rows against the surveillance evidence ledger; the prose is the framing, the rows are the test.
- Annex A — IN SCOPE
47
Annex A controls marked applicable across the ISMS scope — every row in the operational rail that handles merchant or model data carries an applicable mark with a named owner and a re-attestation cadence.
- Annex A — OUT OF SCOPE
11
Annex A controls marked not applicable — one-line rationale per row, typically the ISMS scope edges that don't intersect the operational rail, signed off at the most recent ISMS review window.
- Annex A — EXCLUDED
3
Annex A controls excluded with a written justification — surfaced row-by-row on the SoA so the auditor reads the rationale and the ISMS scope edge without ambiguity.
- A.7 physical controls — remote-first ISMS scope, no owned physical perimeter.
- A.11 physical and environmental security — cloud-hosted production rail, no on-prem hardware.
- A.11.2.7 secure disposal — no owned hardware endpoints, only managed cloud region teardowns under the DPA exit plan.
- A.5 · A.8
AR·Asset register
Asset management
Every system, data store and SaaS dependency that holds merchant or model data sits on the ISMS asset register with a data classifier, a named owner and a re-attestation cadence. The asset register is the one source the auditor diffs against when a new connector ships or a data store moves region — production drifts surface in the same review window as the surveillance audit.
- A.5 · A.8
AC·Access control
Access control
RBAC, MFA and just-in-time admin on every privileged path; segregation of duties between the engineer who ships the lever and the engineer who approves it. The audit ledger is append-only, journalised per action with who/what/against-which-guardrail, and reviewed at the quarterly ISMS window.
- A.5
IR·Incident response
Incident response
A named on-call rotation, a documented severity ladder, a customer-comms tree, and a post-incident review at the next ISMS cycle. Every incident carries a timeline, a root-cause row and a control-treatment entry — so the next surveillance audit reads what changed, not just what happened.
- A.8
SE·Secrets & encryption
Encryption
Data in transit over TLS 1.2+ on every connector, data at rest with envelope encryption per region, key rotation on the documented cadence, and key custody split between the security and platform teams. The key rotation log is part of the surveillance evidence ledger the auditor pulls.
- A.5
SR·Supplier risk
Supplier relationships
Every external processor passes the supplier onboarding flow — security review, DPA, sub-processor responsibilities and exit plan — before it touches merchant data. The supplier register is the same list the GDPR DPA references; a new connector that touches merchant data cannot ship without a row on it.
Data in scope · ISMS asset register
Assets + ingest surfaces the ISMS covers.
The Helmsway ISMS asset register names every data store and ingest surface that holds merchant or model data — with a classifier, a named owner and a re-attestation cadence. The operational ingest point the ISMS is written against is the Shopify connector, with every pickup journalised to the append-only audit ledger. The /integrations/shopify landing walks the connector data shape end to end so a reviewer can read the ingest surface in the same assessment pass.
Risk treatment plan
How each named ISMS risk is treated.
Every named ISMS risk carries a treatment choice, a residual tier and the next review window. The risk register is the same booklet the surveillance audit diffs at the next window — four named rows below, written against the ISMS scope the SoA booklet declares.
Privileged-path misuse
JIT admin + two-person approval + append-only ledger
Residual: Low
External-processor data exposure
Supplier onboarding flow + DPA + monthly vendor-risk review
Residual: Low
Key custody single point of failure
Key custody split between security and platform teams + rotation cadence
Residual: Low
Incident-response drift
Named on-call + severity ladder + customer-comms tree + post-incident review
Residual: Medium
Request the latest ISO 27001 report.
The full ISO/IEC 27001 statement of applicability, the surveillance audit trail, the Annex A risk treatment plan and the latest audit window ship on a mutual NDA under one business day. Send a note and the security contact comes back to you directly.
Replies land with the security contact, not a sales sequence.
- SOC 2
SOC 2 — Type II
Operational controls across the platform — Trust Services Criteria decomposition, control walkthroughs, evidence ledger.
- ISO 42001
ISO/IEC 42001
AI management system — AIMS controls, dataset lineage, prompt-injection guardrails, human oversight.
See it on your store
See it on your store →
Skip the questionnaire — book a Scale-tier demo and watch the helm pull a lever on your Shopify store.
ISO/IEC 27001 covers the information security management system — Annex A controls, the statement of applicability, and the surveillance audit trail. This page walks the framework, the controls in scope across asset management, access control, incident response, encryption and supplier relationships, and how to request the latest report.
← Back to trust center