Where we stand, stated plainly

Built to the practice.
Not yet certified.

Plenty of vendors put certification badges on a page and sort out the details later. Here is our actual position, and — separately — how ARGUS helps you with your own certification, which is the part that matters to your auditor.

The question it comes down to

"Are you certified?"

The answer is no, and you should hear it from us rather than discover it in procurement. What we do have is a documented control environment, written policies, an asset and risk register, and a deployment model in which your data never reaches us in the first place.

Why ordinary search does not get there

A certificate is not the same as a control.

For a supplier whose software runs inside your perimeter, what matters operationally is the deployment model, not a logo. We would rather be judged on the architecture.

Type II needs history.

A SOC 2 Type II report requires evidence that controls operated over a period. That period cannot be compressed, and claiming otherwise would be a lie with a date on it.

Your audit is the one under time pressure.

Whatever our status, your auditor will ask you for evidence per control. That is document work, and it is where a reasoning layer earns its place.

A worked example

The query

Which document evidences that access rights are reviewed, and when did it last happen?

  1. 01
    Access control policy, section 10

    Defines the quarterly review obligation and who owns it.

  2. 02
    Onboarding and offboarding procedures

    Describe how rights are granted and withdrawn in practice.

  3. 03
    Review records

    Show the dates on which reviews were actually performed.

  4. 04
    Risk register entry

    Links the control to the risk it treats.

The answer

A control narrative with four cited sources — and, where a quarter has no review record, that quarter named rather than glossed over.

What ARGUS does here

Control-to-evidence mapping

Annex A controls or Trust Services Criteria are mapped to the policies, procedures and records that evidence them, each with a citation.

Gap reporting that auditors accept

Where evidence is missing for a period, the output names the period and the control instead of producing a comfortable summary.

Statement of Applicability support

Applicability decisions can be traced back to the risk assessment that justifies them, rather than being asserted.

Your data stays yours

The deployment model means our certification status is not a data-protection question for you: your documents never reach our infrastructure.

What it does not do

Stated here rather than discovered in week three of a pilot.

  • Heabsy holds no ISO 27001 certificate and no SOC 2 report today. The security architecture is built along both frameworks; formal certification is planned, not achieved.
  • ARGUS does not grant you certification and is not an audit tool in the assurance sense.
  • It reports on the evidence you index. A control that was never documented reads as a gap, correctly.
  • We will provide our policy set, asset inventory and risk register on request — that is what exists, and it is what we will show.

Questions we get asked

Will you commit to a certification date?+
We will tell you what stage the work is at when you ask, and we will not name a date we cannot hold. For most deployments the more relevant question is the architecture, because the software runs on your side.
Can we run a security review before a pilot?+
Yes, and we prefer it. Architecture documentation, deployment model, data flows and the policy set are available for review under NDA.
What about a DPA?+
Available. In the on-premise deployment model there is typically little or no processing on our side, which usually simplifies the agreement considerably.

Test it on a question you already lost time on

Bring one question your own documents should be able to answer, and the documents that ought to contain the answer. If the evidence is not there, that is the result — and it is worth knowing before an auditor finds it.