compliance
ISO 27001 — Information Security
How QEHS both supports an ISO 27001 ISMS for customers (evidence artefacts) and is itself operated under ISO 27001 controls (our certification posture).
10 min read · 3 sections
Overview
ISO 27001:2022 is the information security standard. The certified entity maintains an Information Security Management System (ISMS) and applies controls from Annex A.
Our posture
- QEHS platform is operated under an ISO 27001 ISMS. Certificate available on request / in the Trust Center.
- Annual surveillance audits by accredited registrar.
- Shared responsibility model — customer owns identity, access, and their tenant data; we own platform confidentiality, integrity, and availability.
Supporting your ISMS
For customers running their own ISMS, QEHS modules can host the asset inventory, risk register, SoA, control evidence, awareness training records, and internal audit programme. The Documents module enforces versioned approval for policies, and the Audit log is tamper-evident (hash-chained, 1–7 years retention).