Innovation & tips

In black and white: xappido is certified to ISO/IEC 27001

A certificate alone does not make software secure. What counts is the work behind it: defined processes, clear responsibilities and careful handling of information. Since June 2026 that has been independently audited and confirmed at xappido.

Information security is hard to show. You cannot see it on the screen, and in everyday project work it usually only becomes noticeable when something is missing. So we are pleased that we can now provide evidence of it: an independent certification body has certified xappido to ISO/IEC 27001:2022, the internationally recognised standard for information security.

Being certified does not mean we bought a particular piece of software. The standard does not prescribe any technology. It requires a management system: transparent rules for how a company handles information, who is responsible for what, and how both are reviewed and developed further.

What the standard requires

It begins with an unspectacular question: what information do we actually hold, and how much protection does each part of it need? Out of the answer come policies, responsibilities and a classification – because not everything is equally sensitive, and treating everything with the same rigour ends up treating nothing properly.

Then comes the risk assessment. Where can something go wrong, how likely is it, and how large would the impact be? Only once that is on the table can you decide which measures are really needed. That is exactly the order in which we worked: first the overview, then the rules, then the measures, and finally the review of how well they work.

What the certificate covers

A certificate always applies to a defined scope, and that scope is stated on the document. Ours covers the design, development, implementation, maintenance and operation of software solutions and the services associated with them.

That is deliberately the whole chain, not merely the administration in the background: from the first concept, through development in our offices in Sursee, to operating the solution that then runs every day.

If you would like to read it: the certificate is available as a PDF – registration number 226-06-018.I, valid until 17 June 2029. The document is in German.

What this means for your projects

The difference from a self-declaration is the independent body. It is not us confirming that our processes are sound, but a certification body that has examined them – one that comes back: the next surveillance audit is due in June 2027. A management system that exists only on paper does not survive that.

For you that means three things. You know how we handle your information, because it is governed by rules and does not depend on whoever happens to be working on the project. You can point to the evidence wherever information security has to be demonstrated, in a tender for example. And the security questions get asked early rather than shortly before go-live – because with us they are part of how we work.

The road there, documented in public

We showed the road to certification from the beginning instead of presenting only the result. In a three-part video series, Sandra from our ICT and project management explains how we went about it: from the process map as the foundation, through policies and the classification of information, to the risk analysis. And then the moment the series builds up to – the certificate in hand.

Information security stays invisible as long as it works. Even so, it can now be proven.

Videos on this topic

Share on LinkedIn ← All insights

More from this category

Innovation & tips

Why we do not start software projects with code

Many software projects start with a concrete idea – an app, say, or a customer portal. But is that always the right solution? Why we deliberately start with a workshop – and why the right questions often matter more than the technology.

Innovation & tips

Campus Sursee Design Sprint

What does a Design Sprint actually deliver? Campus Sursee tried it with us and knew after four days which next step was worth taking.

Innovation & tips

From idea to real customer feedback in four days!

Prepare your digital project with the xappido Design Sprint! In just four days you get clear results and a solid road map before a single line of code is written. Minimise the risks, maximise the prospects of success and get going!

Ready for the next step?

A no-obligation intro call: in 30 minutes you will know what is possible.

Or directly: info@xappido.com

You will not find a phone number here, and that is deliberate: our lines belong to our customers, not to cold callers. Leave us your number and we will be glad to call you back.

Manuel Wymann, Managing Partner & Co-Founder
“How we handle information follows set rules and is independently audited. Ask us about it and we will show you what that means for your task.”
Manuel Wymann · Managing Partner & Co-Founder