Security Program: ISO 27001 & SOC 2 Alignment

Short version: Web Tonic operates an information security program built to ISO/IEC 27001 Annex A control themes and the SOC 2 Trust Services Criteria. We are not certified under either framework and hold no audit report. This page publishes the controls themselves so your reviewer can assess us on evidence rather than on a badge.

Control matrix

Mapped to the four ISO/IEC 27001:2022 Annex A themes.

Organizational controls

  • Written information security and acceptable-use policies, acknowledged by every team member at onboarding and annually thereafter.
  • Named security owner accountable for the program; policy review at least annually.
  • Vendor risk review before a new subprocessor is engaged, with the list published at /trust/subprocessors and 30 days’ notice before additions.
  • Contractual data protection terms with every subprocessor, including flow-down of client obligations on regulated engagements.
  • Client data classified on engagement start; engagements involving PHI or special-category data are flagged and staffed accordingly.
  • Documented incident response procedure with a 48-hour client notification commitment from confirmation.

People controls

  • Background and reference checks on hire; confidentiality obligations in every contractor and employee agreement.
  • Annual security and privacy awareness training; role-specific HIPAA training for healthcare account staff.
  • Documented offboarding checklist; all access revoked within one business day.
  • Phishing and social-engineering awareness, with a no-blame internal reporting path.

Physical controls

  • Distributed team; no client data held on unmanaged local storage as a system of record.
  • Full-disk encryption and screen lock required on every device with client access.
  • Client data at rest lives in access-controlled cloud services, not on portable media.

Technological controls

  • MFA enforced on every platform and internal account; SSO where the platform supports it.
  • Least-privilege role assignment, per engagement, reviewed on change.
  • Password manager mandatory; no credential sharing over email or chat.
  • TLS in transit and provider-managed encryption at rest across our stack.
  • Managed endpoints with OS and browser auto-update and disk encryption.
  • Logging and access history retained in the underlying platforms for investigation.
  • Change control on client websites: staging or backup before deployment, and rollback capability.
  • Backups for systems we host, with restore tested on a defined cadence.

How far our assurance extends

  • ISO/IEC 27001: program alignment, self-assessed — no certificate issued by an accredited certification body.
  • SOC 2: controls mapped to the Trust Services Criteria — no Type I or Type II report.
  • Penetration testing is scoped to the client web properties we build and maintain, not to our own corporate perimeter, so there is no internal test report to share.
  • Incident detection runs on business-hours review plus automated platform alerting, rather than a 24/7 security operations centre.
  • We are a marketing agency, not a hosting or security vendor. Where you need certified infrastructure, we work inside yours.

Frequently asked by security reviewers

Is Web Tonic ISO 27001 certified?

No. Our security program uses ISO/IEC 27001 as its reference framework and our team is experienced operating inside client environments governed by it, but Web Tonic does not hold a certificate issued by an accredited certification body. Under the standard’s own logic, an organization may implement ISO 27001 internally without engaging a certification body — that state is correctly described as “aligned with” or “conforming to” ISO 27001, never “certified.” We also do not use the ISO logo, which is trademarked and off-limits even to certified organizations.

Do you have a SOC 2 report?

Not today. Our controls are mapped to the SOC 2 Trust Services Criteria for security, availability and confidentiality, and we can walk your reviewer through that mapping, but there is no Type I or Type II report to hand over. If a report is a hard gate in your process, say so on the first call and we will scope the engagement to run inside your own audited environment.

What is the difference that matters to us as a buyer?

Certification transfers assurance from us to an independent auditor. Alignment does not. It means you are relying on our documented controls and your own diligence instead of an accredited auditor’s opinion. For most marketing engagements — where we hold delegated platform access rather than your production data — that is a proportionate risk position. For engagements where we would hold regulated data at scale, it may not be, and we will say so.

How do you protect access to our advertising and analytics accounts?

We prefer delegated access to your own accounts over creating parallel ones, so ownership never leaves you. Every Web Tonic user is a named individual with MFA enforced, granted the minimum role that allows the work, reviewed on staffing change, and removed within one business day of offboarding. We do not share credentials, and we ask clients never to send them by email or chat.

Do you use AI tools on our data?

Yes, for research, drafting and analysis — within limits. Client personal data and any protected health information are excluded from general-purpose AI tools. Where AI is used on client material, it runs under business terms that exclude training on our inputs, and a human reviews every output before it reaches you or the public.

Send us your questionnaire

We complete vendor security assessments on request — [email protected]. Related: Trust & Compliance · HIPAA & healthcare data · Subprocessors · Data processing & GDPR.