ISO 27001 · ISO 9001 · ISO 42001
ISO certifications and AI management verification.
CloudMonitor is certified to ISO/IEC 27001 and ISO 9001 and holds an ISO/IEC 42001 Certificate of Verification from Equal Assurance.
Active assurance
Check the assurance status for each standard.
ISO/IEC 27001:2022
Information Security Management System
ISO 9001:2015
Quality Management System
ISO/IEC 42001
AI Management System · Certificate of Verification
Annual surveillance
Applies to the certified management systems
Statement of Applicability
Available on request
ISO/IEC 27001:2022
Information Security Management.
ISO 27001 is the international standard for information security management. It defines the requirements for an ISMS: a systematic approach to keeping sensitive information secure.
CloudMonitor's ISO 27001 certification covers the design, development, operation, and support of the CloudMonitor FinOps platform, including the FinOps reports, admin app, Teams bot, and supporting infrastructure.
- Annex A controls implemented and assured
- Annual surveillance audits, with full recertification every three years
- Statement of Applicability available under NDA
- Continuous improvement of the ISMS
ISO 9001:2015
Quality Management.
ISO 9001 is the international standard for quality management. It demonstrates that CloudMonitor consistently meets customer requirements through process control, continuous improvement, and customer-focused operations.
In practice, this means our release management, support, and customer success processes are externally audited and held to international standards.
- Customer satisfaction tracked and reported
- Non-conformity management and root-cause analysis
- Process maps and SLAs available on request
ISO/IEC 42001
AI Management System verification.
ISO/IEC 42001 defines requirements for establishing, operating, and improving an AI management system. Equal Assurance has issued CloudMonitor a Certificate of Verification against the standard.
We describe this assurance as verification, not certification. Request the current document through the Security Pack for its status and scope.
FAQ
Assurance questions
Are you ISO certified?
CloudMonitor is certified to ISO/IEC 27001:2022 (Information Security) and ISO 9001:2015 (Quality Management). It holds an ISO/IEC 42001 Certificate of Verification from Equal Assurance. Current assurance documents are available under NDA through the Security Pack; see the certification statement for scope and audit cadence.
Can we get a SOC 2 report?
CloudMonitor does not currently have a SOC 2 report. We can share our current ISO/IEC 27001 certificate and available audit material under NDA through the Security Pack. See the ISO certification statement for scope, certifying body, and audit cadence.
Is CloudMonitor certified by Microsoft?
Yes — CloudMonitor is a Microsoft Solutions Partner with certified software for Azure. The designation confirms the platform has been technically reviewed for interoperability with Microsoft Azure and validated against Microsoft Marketplace customer-success criteria. Procurement teams can reference the Microsoft Learn overview of the designation and the Information Trust Center for CloudMonitor's ISO certifications, ISO/IEC 42001 verification, FinOps Specialty Solution, and Microsoft Solutions Partner status.
How do we get a copy of the certificate?
Request the current assurance documents through our security contact form. The security, privacy, or compliance option is selected automatically. We will confirm any NDA or access requirements for the available documents.
How often are you audited?
ISO/IEC 27001 and ISO 9001 follow annual surveillance and three-year recertification cycles. CloudMonitor holds ISO/IEC 42001 as a Certificate of Verification. Request the current certificates and audit status through the Security Pack.
Need to brief your security team?
We provide NDAs, security questionnaires, and current assurance documents on request.