[{"_id":"6a3e118243ee39e7a8239875","title":"ISO 27001:2022","description":"Auditor: BSI\r\n\r\nThis is our ISO/IEC 27001:2022 certification. The standard provides companies of any size and sector with guidance for establishing, implementing, maintaining, and continually improving an information security management system, ensuring the confidentiality, integrity, and availability of customer data.","accessTier":"private","category":"Compliance","allowedUsers":[],"created_on":"2026-06-26T05:43:30.353Z","updated_on":"2026-06-26T06:02:26.736Z","__v":0},{"_id":"6a3e122243ee39e7a8239878","title":"ISO 27701:2019","description":"Auditor: BSI\r\n\r\nThis is our ISO/IEC 27701:2019 certification. Extending ISO/IEC 27001, this standard specifies requirements for a Privacy Information Management System, demonstrating our commitment to responsibly handling personal data as both a controller and processor.","accessTier":"private","category":"Compliance","allowedUsers":[],"created_on":"2026-06-26T05:46:10.054Z","updated_on":"2026-06-26T06:03:11.775Z","__v":0},{"_id":"6a3e126d33f368a4694b0d05","title":"ISO 9001:2015","description":"Auditor: BSI\r\n\r\nThis is our ISO 9001:2015 certification. The standard sets out the criteria for a Quality Management System, reflecting our commitment to consistently meeting customer and regulatory requirements and continually improving operational quality.","accessTier":"private","category":"Compliance","allowedUsers":[],"created_on":"2026-06-26T05:47:25.835Z","updated_on":"2026-06-26T06:09:27.565Z","__v":0},{"_id":"6a3e12c73ba33567fa96e247","title":"ISO 27017:2015","description":"Auditor: BSI\r\n\r\nThis is our ISO/IEC 27017:2015 certification. The standard provides a code of practice for information security controls specific to cloud services, defining the security responsibilities shared between Darwinbox and our customers across our SaaS.","accessTier":"private","category":"Compliance","allowedUsers":[],"created_on":"2026-06-26T05:48:55.850Z","updated_on":"2026-06-26T06:04:05.228Z","__v":0},{"_id":"6a3e131b43ee39e7a823987d","title":"ISO 27018:2019","description":"Auditor: BSI\r\n\r\nThis is our ISO/IEC 27018:2019 certification. The standard provides a code of practice for protecting personally identifiable information (PII) in public cloud environments, validating the controls we apply when processing personal data as a processor.","accessTier":"private","category":"Compliance","allowedUsers":[],"created_on":"2026-06-26T05:50:19.976Z","updated_on":"2026-06-26T06:08:07.138Z","__v":0},{"_id":"6a3e1525cd333884a4f57ff2","title":"SOC 2 Type II","description":"Auditor: KPMG\r\n\r\nThis is Darwinbox's SOC 2 report. This is an attestation that evaluates our company's ability to securely manage the data we collect from our customers and use during business operations.","accessTier":"private","category":"Compliance","allowedUsers":[],"created_on":"2026-06-26T05:59:01.016Z","updated_on":"2026-08-21T09:44:31.529Z","__v":0},{"_id":"6a3e183943ee39e7a82398a1","title":"SOC 1 Type II","description":"Auditor: KPMG\r\n\r\nThis is Darwinbox's SOC 1 report. This is an attestation that evaluates the design and operating effectiveness of our controls relevant to our customers' internal control over financial reporting.","accessTier":"private","category":"Compliance","allowedUsers":[],"created_on":"2026-06-26T06:12:09.007Z","updated_on":"2026-08-18T00:00:01.548Z","__v":0},{"_id":"6a3e18d53ba33567fa96e270","title":"GDPR","description":"This is Darwinbox's GDPR compliance attestation, evaluating our ability to protect the personal data of EU individuals and uphold their privacy rights under the General Data Protection Regulation.","accessTier":"private","category":"Compliance","allowedUsers":[],"created_on":"2026-06-26T06:14:45.042Z","updated_on":"2026-06-26T06:14:45.042Z","__v":0},{"_id":"6a3e197743ee39e7a82398a4","title":"CCPA/CPRA","description":"This is Darwinbox's CCPA/CPRA compliance attestation, evaluating our ability to protect the personal information of California residents and uphold their privacy rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.","accessTier":"private","category":"Compliance","allowedUsers":[],"created_on":"2026-06-26T06:17:27.363Z","updated_on":"2026-06-26T06:17:27.363Z","__v":0},{"_id":"6a3e19da3ba33567fa96e273","title":"Darwinbox DPA","description":"This is Darwinbox's Data Processing Agreement (DPA), setting out the terms under which we process personal data on behalf of our customers as a processor, in line with applicable data protection laws.","accessTier":"private","category":"Compliance","allowedUsers":[],"created_on":"2026-06-26T06:19:06.010Z","updated_on":"2026-06-26T06:19:06.010Z","__v":0},{"_id":"6a3e1a8d43ee39e7a82398a9","title":"Information security and Privacy Management system policy","description":"This is Darwinbox's Information Security and Privacy Management System Policy, establishing the framework and commitment for protecting the confidentiality, integrity, and availability of information and the responsible handling of personal data across the organization.","accessTier":"private","category":"Policies","allowedUsers":[],"created_on":"2026-06-26T06:22:05.546Z","updated_on":"2026-06-26T06:22:05.546Z","__v":0},{"_id":"6a3e1add3ba33567fa96e276","title":"Information Security Incident Management & Privacy Incident Management","description":"This is Darwinbox's Information Security and Privacy Incident Management Policy, defining the process for identifying, reporting, responding to, and resolving security and privacy incidents in a timely and effective manner.","accessTier":"private","category":"Policies","allowedUsers":[],"created_on":"2026-06-26T06:23:25.197Z","updated_on":"2026-06-26T06:23:25.197Z","__v":0},{"_id":"6a3e1b3543ee39e7a82398ac","title":"Darwinbox Privacy Policy","description":"This is the Darwinbox Privacy Policy, describing how we collect, use, store, and protect personal data, and how individuals can exercise their privacy rights.","accessTier":"public","category":"Policies","allowedUsers":[],"created_on":"2026-06-26T06:24:53.204Z","updated_on":"2026-08-20T09:56:04.825Z","__v":0},{"_id":"6a3e1bec43ee39e7a82398cb","title":"Third Party Management Policy","description":"This is Darwinbox's Third Party Management Policy, establishing the requirements for assessing, onboarding, monitoring, and managing the security and privacy risks associated with third-party vendors and service providers.","accessTier":"private","category":"Policies","allowedUsers":[],"created_on":"2026-06-26T06:27:56.801Z","updated_on":"2026-06-26T06:27:56.801Z","__v":0},{"_id":"6a3e1c5d3ba33567fa96e28b","title":"Backup Business Continuity and Disaster Plan Policy","description":"This is Darwinbox's Backup, Business Continuity, and Disaster Recovery Policy, defining the requirements for data backup, service resilience, and the recovery of critical operations to ensure continuity in the event of a disruption.","accessTier":"private","category":"Policies","allowedUsers":[],"created_on":"2026-06-26T06:29:49.864Z","updated_on":"2026-06-26T06:29:49.864Z","__v":0},{"_id":"6a82dd37220225d4aa5416ad","title":"ISO 42001:2023","description":"Auditor: TÜV SÜD\r\n\r\nThis is our ISO/IEC 42001:2023 certification. The standard provides companies of any size and sector with guidance for establishing, implementing, maintaining, and continually improving an artificial intelligence management system, ensuring the responsible development, provision, and use of AI systems with due regard to safety, fairness, transparency, and accountability.","accessTier":"private","category":"Compliance","allowedUsers":[],"created_on":"2026-08-17T10:06:47.234Z","updated_on":"2026-08-17T10:06:47.234Z","__v":0}]