Optit has achieved ISO/IEC 27001:2022 certification, the international standard that sets out the requirements for an information security management system.

The certificate was issued by DNV Business Assurance, an ACCREDIA-accredited body, and confirms that the way we manage information (our clients’ information, our project information and the information that feeds our models) meets the most rigorous criteria recognised internationally.

Why it matters for Decision Intelligence

Data is the starting point of every project we take on: the raw material we use to help complex organisations decide better. Anyone who entrusts us with their data is entrusting us with something valuable.

The certification covers a precise scope: the design, development, delivery and maintenance of software solutions and services that incorporate artificial intelligence algorithms — whether on-premise or delivered via Cloud/SaaS — along with AI-based technology consulting and business consulting services. In other words, exactly what we do.

Better decisions require data you can trust, and information security is what makes that trust possible.

This certification is a further step on a path we have been following for some time: making sure the data entrusted to us is always managed and protected to the highest security standards.

Nine months to build a security management system

Achieving certification took nine months of work. Not to compile a manual, but to build an information security management system that lives in our day-to-day processes.

  • We defined policies and procedures for incident and change management.
  • We carried out risk analysis and put business continuity in place, so we know in advance how to react when something goes wrong.
  • We aligned GDPR requirements with those of the standard, so that data protection and information security speak the same language.
  • We redesigned the way we manage suppliers, clients and documentation, and strengthened our secure software development practices across the entire product lifecycle.
  • And, above all, we trained everyone on the team.

Security isn’t a technical safeguard left to a few: it’s a way of working shared by everyone. A system is only as strong as the habits of the people who use it every day.

This is the deeper meaning of the standard. ISO/IEC 27001 does not certify a moment in time, but a method: the ability to manage risk continuously, measurably and in a way that can be verified by an independent third party.

What changes for our clients and partners

The certification has concrete effects:

  • It reduces the risk of incidents and the costs they bring, because structured prevention costs less than chasing problems after the fact.
  • It strengthens our compliance and data protection posture.
  • It gives clients, partners and the market a verifiable signal: at Optit, security is not a statement of intent but a system certified by an independent body.

For those who choose to work with us, all of this translates into a simpler, stronger credential to point to and one more guarantee.

A starting point

We see ISO/IEC 27001 not as a destination, but as a milestone along the way — one to keep building on. The same dedication we bring to helping our clients make better decisions, we apply to the way we protect the information entrusted to us.

After all, anyone who makes decisions based on data needs to be able to trust the way that data is safeguarded.