Security & Compliance | ISO/IEC 27001:2022 Certified - SJ Innovation
SJ Innovation is ISO/IEC 27001:2022 certified. Learn about our access controls, data protection, risk management, incident response, and compliance practices.
Security you can verify
Your data, your clients' data, and your code sit inside our systems every day. We treat that as the job, not the paperwork.
SJ Innovation Private Limited is certified to ISO/IEC 27001:2022, the international standard for information security management.
What this means in practice
Confidentiality
Access to client data is granted by role, reviewed regularly, and removed the day someone leaves the project or the company.
Changes to client systems and data are logged, reviewed, and traceable to a named person.
Availability
Backup, recovery, and business continuity plans are documented and tested across all three delivery centers.
Our controls
Access control
Role-based access, least privilege, mandatory MFA on company systems, documented onboarding and offboarding.
Data protection
Encryption in transit and at rest. Client data stays inside approved systems and is never used outside the engagement.
Risk management
A live information-security risk register. Risks are assessed, treated, and reviewed by management.
Incident response
Documented process with severity levels, escalation path, and client notification commitments.
Background verification, signed confidentiality agreements, annual security awareness training for every employee.
Supplier security
Third-party tools and subcontractors are reviewed before client data goes near them.
AI and your data
- Client data is never used to train public AI models.
- AI features run through approved enterprise providers under commercial terms, not consumer accounts.
- For clients who need it, AI processing can run inside your own infrastructure. Nothing leaves your firewall.
- Every AI agent we deploy is logged and auditable.
Regulated industries
We deliver into healthcare, mortgage, financial services, and the nonprofit sector. Where a client operates under HIPAA, GDPR, or similar obligations, we build to those requirements and sign the agreements that go with them, including BAAs and DPAs.
Security questionnaires and due diligence
We can provide:
- The certificate and scope statement
- An information security policy summary
- A completed standard security questionnaire
- NDA / DPA / BAA where applicable
- A call with technical leadership
Send requests to security@sjinnovation.com. If needed, use business@sjinnovation.com.
Continual improvement
Certification is a starting line, not a trophy. We run internal audits, management reviews, and risk reassessments on a fixed schedule, and we are audited annually by [CERT BODY].
Have a security question before you sign?
Ask it now, not after the contract.