Built to the practice.
Not yet certified.
Plenty of vendors put certification badges on a page and sort out the details later. Here is our actual position, and — separately — how ARGUS helps you with your own certification, which is the part that matters to your auditor.
"Are you certified?"
The answer is no, and you should hear it from us rather than discover it in procurement. What we do have is a documented control environment, written policies, an asset and risk register, and a deployment model in which your data never reaches us in the first place.
Why ordinary search does not get there
A certificate is not the same as a control.
For a supplier whose software runs inside your perimeter, what matters operationally is the deployment model, not a logo. We would rather be judged on the architecture.
Type II needs history.
A SOC 2 Type II report requires evidence that controls operated over a period. That period cannot be compressed, and claiming otherwise would be a lie with a date on it.
Your audit is the one under time pressure.
Whatever our status, your auditor will ask you for evidence per control. That is document work, and it is where a reasoning layer earns its place.
A worked example
Which document evidences that access rights are reviewed, and when did it last happen?
- 01Access control policy, section 10
Defines the quarterly review obligation and who owns it.
- 02Onboarding and offboarding procedures
Describe how rights are granted and withdrawn in practice.
- 03Review records
Show the dates on which reviews were actually performed.
- 04Risk register entry
Links the control to the risk it treats.
A control narrative with four cited sources — and, where a quarter has no review record, that quarter named rather than glossed over.
What ARGUS does here
Control-to-evidence mapping
Annex A controls or Trust Services Criteria are mapped to the policies, procedures and records that evidence them, each with a citation.
Gap reporting that auditors accept
Where evidence is missing for a period, the output names the period and the control instead of producing a comfortable summary.
Statement of Applicability support
Applicability decisions can be traced back to the risk assessment that justifies them, rather than being asserted.
Your data stays yours
The deployment model means our certification status is not a data-protection question for you: your documents never reach our infrastructure.
What it does not do
Stated here rather than discovered in week three of a pilot.
- Heabsy holds no ISO 27001 certificate and no SOC 2 report today. The security architecture is built along both frameworks; formal certification is planned, not achieved.
- ARGUS does not grant you certification and is not an audit tool in the assurance sense.
- It reports on the evidence you index. A control that was never documented reads as a gap, correctly.
- We will provide our policy set, asset inventory and risk register on request — that is what exists, and it is what we will show.
Questions we get asked
Will you commit to a certification date?+
Can we run a security review before a pilot?+
What about a DPA?+
Test it on a question you already lost time on
Bring one question your own documents should be able to answer, and the documents that ought to contain the answer. If the evidence is not there, that is the result — and it is worth knowing before an auditor finds it.