1. Home
  2. Welcome
  3. Trust Portal

Trust Portal

Our Trust Portal is where we publish the evidence behind OpenCorporates’ security and privacy posture.

On this page you will find information on our current ISO certifications, instructions for verifying them independently with our certification body, a summary of the controls we operate, and our answer to the question we are asked most often: what we hold in place of a SOC 2 report.

Our certifications

OpenCorporates holds two active, independently audited certifications, covering information security and privacy respectively. Both are issued by DNV, an accredited third-party registrar.

ISO/IEC 27001:2022 — Information Security Management System

Certified entityOpencorporates Ltd
Certificate numberC641398
Certification bodyDNV Business Assurance UK Limited, London
Initial certification22 December 2023
Valid22 December 2023 – 21 December 2026

Scope of certification, as stated on the certificate:

Processing and storage of corporate data, provision of database activities and access to information on demand in accordance with SoA version 1.1.

Download the ISO/IEC 27001:2022 certificate (PDF)

ISO/IEC 27701:2025 — Privacy Information Management System

Certified entityOpencorporates Ltd
Certificate numberC876699
Certification bodyDNV Business Assurance B.V., Barendrecht, Netherlands
Initial certification25 August 2026
Valid25 August 2026 – 24 August 2029

Scope of certification, as stated on the certificate:

Processing and storage of corporate data, provision of database activities and access to information on demand in the context of a PII Controller and Processor in accordance with SoA version 1.06.

Download the ISO/IEC 27701:2025 certificate (PDF)

Our privacy certification covers us acting as both a PII controller and a PII processor. Many privacy certifications are scoped to one role only, which leaves a gap when you need assurance about the other.

We are certified against ISO/IEC 27701:2025, the current version of the standard. This is significantly more demanding than the 2019 version.

Verify these certificates yourself

A certificate PDF, on its own, does not prove much. Certificates are straightforward to forge, and the most common approach is to take a genuine expired certificate number and edit the dates. If you are assessing us properly, you should check our certificates against our certification body’s own records rather than against a document we handed you.

There are two ways to do that, and we would encourage you to use whichever you trust most.

1. Check our certificates directly

These links query DNV’s certificate register for our two certificate numbers:

2. Search DNV’s register yourself

If you would prefer not to follow a link we have constructed, go to DNV’s public certificate checker at certificatechecker.dnv.com and enter the certificate numbers yourself. They are C641398 for ISO/IEC 27001:2022 and C876699 for ISO/IEC 27701:2025.

When you check, we would suggest confirming three things: that both certificates are currently in date, that the certification body is DNV, and that the scope of certification matches the services you intend to use. Scope is the detail most worth your attention, as a certificate can be entirely genuine and still cover a fraction of an organisation’s operations.

Statement of Applicability summary

The Statement of Applicability is the document that records which controls from each standard we have brought into scope, and justifies any we have excluded. It is the fastest way to tell whether a certification reflects a serious programme or a minimal one.

We operate the complete control set of every standard we are certified against, with three narrow exceptions, each documented and justified below.

ISO/IEC 27001:2022

All clauses are in scope. The standard requires this, and we meet it in full.

ISO/IEC 27002:2022 (Annex A to ISO/IEC 27001)

All controls are in scope, with the following three exceptions:

ControlWhy it is out of scope
7.6 Working in secure areasWe operate a distributed workforce and do not maintain designated secure areas. Client conversations and analytical work take place in home offices or private areas of shared offices, which we assess as sufficient protection against the bystander risk involved.
8.11 Data maskingOur data is drawn from official public registers and is published as a matter of course. Masking it would not deliver a meaningful reduction in risk relative to the effort required.
8.30 Outsourced developmentWe do not outsource development. Contract developers work on OpenCorporates systems, under OpenCorporates standards and ways of working, so they are governed by our internal development controls rather than by a separate outsourcing regime.

Anything not listed above is in scope, has been assessed, and is covered by our audits.

ISO/IEC 27701:2025

All controls are in scope. There are no exclusions.

This covers the controls for organisations acting as a PII controller, the controls for organisations acting as a PII processor, and the shared security controls that carry a direct privacy impact. Taking both the controller and processor control sets in full is a deliberate choice, and it is reflected in the scope statement on our certificate.

Why we don’t have SOC 2

We do not hold a SOC 2 attestation. We hold ISO/IEC 27001:2022 and ISO/IEC 27701:2025 certifications, which together cover the same ground that a SOC 2 Type II audit examines.

How the two frameworks compare

Compliance domainISO/IEC 27001 + ISO/IEC 27701SOC 2 (Type II)
Security controlsCovered. Governed under our certified ISO 27001 ISMS, spanning access control, network security, and operational resilience.Covered. Evaluated under the Security Trust Services Criteria.
Data protection and PIICovered as standard. Explicitly governed under our certified ISO 27701 PIMS, across both controller and processor roles.Optional. Not assessed unless the customer scopes in the Privacy Trust Services Criteria.
Independent verificationAudited and certified by an accredited independent third-party registrar, with surveillance audits across a three-year certification cycle.Audited annually by an independent Certified Public Accountant firm.
Basis of assessmentAssessed against a prescribed international control set defined by the standard.Assessed against controls the organisation selects and describes itself, mapped to the Trust Services Criteria.
RecognitionAn international standard, recognised across jurisdictions and by multinational regulatory bodies.Widely recognised, principally in North America.

We are not arguing that one framework is better than the other. The point is that they are addressed to the same question, and that our certifications answer it with third-party verification against an externally defined control set.

What this means for your due diligence

Information security governance. Our ISO 27001 certification provides external validation of our risk management, threat monitoring, business continuity planning, and physical and logical access controls.

Privacy and data protection. Our ISO 27701 certification independently validates our controller and processor workflows, which are the workflows that carry our obligations under the UK GDPR, the Data Protection Act 2018, and equivalent international data protection law.

Audit efficiency. Because the framework is externally audited and covers both security controls and privacy management, it is generally sufficient to satisfy enterprise security questionnaires and vendor risk assessments without a separate exercise.

Updated on September 3, 2026
Was this article helpful?

Related Articles

Need Support?
Can’t find the answer you’re looking for? Don’t worry we’re here to help!
Contact Support