With this in mind, Shipfix was founded with security and privacy as a core value. Obtaining and maintaining ISO 27001 and 27701 certifications is our chance to demonstrate our commitment to this value with the help of an internationally recognised standard.
ISO 27001 provides standard requirements for establishing, implementing, maintaining and continually improving an information security management system. ISO 27701 is an extension of the former focused on Personally Identifiable Information (PII) and privacy.
In practice, it ensures that we have the best practices implemented for Security and Privacy whilst ensuring:
At Shipfix, we aspire to nothing less than excellence and we make it our top priority day after day. Our client's interests always come first and we protect their privacy and security accordingly.
We’ve been saying this since day 1 but we wanted to go even further and to demonstrate this commitment.
We want Shipfix to lead by example in the market and to be seen as the industry reference with regards to the protection of information and privacy.
These two certifications will ensure peace of mind not only for ourselves but most importantly for our clients, even the most demanding of them, by providing the highest level of protection for their organisation, their assets and safety.
Article 42 of the GDPR encourages the establishment of data protection certification mechanisms. No such mechanism has yet been officially recognised by the EU but in our view ISO 27701 is the best mechanism available at the moment.
We’ve committed all resources at our disposal and worked tremendously hard over the last 8 months to pass these two certifications but it’s not over yet. We must continue our efforts to guarantee security and privacy over time. Each year our management system will be checked by external auditors and every three years we will need to pass a full audit. So this is only the beginning of the story.
It will provide the assurance that we have in place a strict security and privacy program assessed by an independent third party to meet the most demanding international standards.
You can rest assured that:
Our existing customers welcome this significant qualification and we are already noticing a clear mark of interest amongst the larger listed and regulated organisations looking to revamp their trading and chartering setup as they see the opportunity to partner with an organisation that shares their high standards.
It will also allow us to maintain our current growth rate without compromising security and privacy, for example, it facilitates the onboarding of new Shipfix staff with clearer guidelines and policies. We boost operational agility. Everything we do is documented and it helps us sleep better at night knowing that we have implemented the most secure environment for our clients and ourselves.
One of the first requirements for this certification is that “top management shall demonstrate leadership and commitment with respect to the information security management system”. As CFO and COO of Shipfix, I’ve been running this project since my first day at Shipfix and I would like to thank our co-founders and co-CEO for their dedication to this certification. They led by example and understood very well the meaning of leadership and commitment.
A BIG thank you to the entire Shipfix team who spent time answering my endless list of questions and for having embraced our new security and privacy standards.
We could not have achieved this certification in such a short period of time without amazing partners and advisors. Thank you to the entire team at Akant, our advisors, and particularly to Damien Peschet and Philippe Labare. They’ve worked relentlessly to help us get to speed and most importantly make us understand the mindset behind such certifications.
Also thanks to Jackie Fronheiser from Vanta for her assistance. Vanta is a great tool to simplify and automate many of the complex and time consuming monitoring required by the ISO norm.
For more information about our experience running the ISO certification or any other questions on our security and privacy management system you can reach out to Gregory Tilmant, our CFO and COO, via privacy@shipfix.com