Trust Centre

Security, compliance and verification at MaxIron

Everything a procurement, security or audit team needs to assess MaxIron in one place: live status of the current ISO/IEC 27001:2022 and ISO 9001:2015 certifications, the sub-processors we use, the security contact and PGP key, and a route to the quarterly Trust Report.

Last updated: 1 May 2026 · Next quarterly review due: 1 August 2026

Live status

Certifications and listings, with the reference to search

Certifications and listings

ISO/IEC 27001:2022
Certified by ISOQAR (UKAS-accredited Certification Body 0026), certificate 27274. Verify on ISOQAR.
ISO 9001:2015
Certified Quality Management System by ISOQAR (UKAS 0026), certificate 27274. Verify on ISOQAR.
UK GDPR / DPA 2018
Compliant. Documented record of processing activities and a DPIA process.
UK G-Cloud 14
Listed, supplier 721548. Verify on Digital Marketplace.
IBM Partner Plus
Gold Partner, company 8294. Verify on ibm.com.
Companies House
MaxIron Ltd, company number 14444817. Verify on Companies House.

ISMS shape

Policies and procedures
26 policies and 11 procedures under the certified Information Security Management System.
Statement of Applicability
Addresses all 93 Annex A controls. Available to customers under NDA on request.
Assurance cadence
Annual internal audit, quarterly performance reporting against defined security objectives, annual management review.
Accreditation recognition
UKAS is an IAF MLA signatory. The certifications are recognised internationally as equivalent to IAF MLA peers including ANAB (United States), JAS-ANZ (Australia and New Zealand) and DAkkS (Germany).

Certified to ISO/IEC 27001:2022 and ISO 9001:2015 by ISOQAR (UKAS-accredited Certification Body 0026), certificate number 27274. Status words on this page are deliberate: Certified, Compliant and Listed are not interchangeable.

Control surface

Six control areas a diligence questionnaire maps onto

Codes C1 to C6 are stable once published, so a questionnaire answer can cite the row rather than paraphrase it.

Ref AreaWhat is in place
C1 Cloud hostingCustomer IBM Maximo environments on AWS, Microsoft Azure or Oracle Cloud Infrastructure, chosen per customer requirement. AWS GuardDuty, Azure Defender and OCI Cloud Guard enabled on all active environments. CloudTrail / Activity Log / Audit logging retained for 12 months. Cloud security alerts reviewed weekly by the security lead. Default data residency UK/Ireland; alternative regions agreed per customer. Shared responsibility formally documented: MaxIron manages identity, patching, encryption, network configuration, monitoring and backup within the customer layer. Cloud infrastructure providers hold SOC 2 Type II and ISO 27001 certifications.
C2 Access and identityMulti-factor authentication enforced on all accounts: cloud console, Microsoft 365, VPN and all SaaS tooling. Least-privilege access with named individual accounts; no shared credentials. Customer environment access via VPN with IP whitelisting. Semi-annual access rights review; access revoked within five business days of any personnel or contract change. Privileged cloud access restricted to a small number of named individuals.
C3 Endpoint and personnelAll endpoints managed under Microsoft Intune (MDM). Full-disk encryption enforced (BitLocker on Windows; FileVault on macOS). Endpoint Detection and Response and antimalware active on all endpoints via Intune. Screen lock, patch compliance and application policies enforced centrally; remote wipe enabled. MDM compliance dashboard reviewed monthly by the security lead. Pre-engagement screening for employees and contractors. NDA and policy acknowledgement required before system or data access. Annual security awareness training using NCSC-accredited content. Dedicated AI use policy: no customer data permitted in unapproved AI services.
C4 Incident and continuityIncident classification P1 to P4 with service-level response times. P1 (critical): one-hour acknowledgement target. Customer notification without undue delay for any incident affecting their environment. Post-incident review and formal corrective action for significant incidents. Evidence preservation and chain-of-custody procedures documented. Business continuity plan covering service disruption, cloud provider failure and key-person scenarios. Backup policy with restore testing at least semi-annually per production environment. ICT recovery planning inside the certified ISO/IEC 27001:2022 ISMS, including control A.5.30.
C5 Platform and portalIBM Maximo Application Suite configured with HTTPS-only access and valid TLS certificates, HTTP-to-HTTPS redirection enforced, role-based access via Maximo security groups, sites and conditions, application-level audit logging, and fix packs applied in line with IBM support timelines and MaxIron vulnerability management. MaxIron Portal: MFA-protected access, role-based permissions, encrypted data in transit and at rest, hosted on MaxIron-managed cloud infrastructure within the ISMS scope.
C6 Suppliers and classificationSuppliers risk-classified across four tiers (Critical, Significant, Standard, Contractor). Tier 1 suppliers (AWS, Azure, OCI, Microsoft 365) assessed annually against published security certifications. Contractual security terms required for all supplier engagements. Contractor access governed by a dedicated onboarding process including NDA, policy acknowledgement, MFA and MDM enrolment. Information classified Public, Internal, Confidential or Restricted. Customer information received during service delivery is treated as Confidential by default unless the customer specifies otherwise.

MaxIron manages the customer layer on the shared responsibility model. Your own Maximo environment configuration outside that layer sits with your organisation unless the contract says otherwise.

Before you request the pack

Four statements that decide whether a diligence request is ready

Run them in order. Stopping early usually means the request needs a named owner or an NDA before the Statement of Applicability can leave the ISMS.

  1. 1

    A named security or procurement contact will receive the pack, and an NDA is available if the Statement of Applicability is required.

  2. 2

    The questions map to published references (certificate 27274, supplier 721548, company 8294) rather than to a narrative brochure.

  3. 3

    Sub-processor change history for the last twelve months is in scope for the quarterly Trust Report.

  4. 4

    Any questionnaire that needs a control owner named against Annex A can be answered from the certified ISMS, not invented for the bid.

If you stopped early

Write to security@maxiron.com with the named contact and whether an NDA is already in place. The pack follows once those two are settled.

If every statement held

Request the Statement of Applicability and the current quarterly Trust Report from security@maxiron.com. Both are produced from the certified ISMS, not assembled for the bid.

Verification

Four checks a reviewer can run without a sales call

Each test names the pass condition and who witnesses it. A claim that cannot fail a public-register check does not belong on this page.

  1. V1

    ISO certifications on the public register

    Passes when
    Search 27274 on the ISOQAR register returns ISO/IEC 27001:2022 and ISO 9001:2015, issued by UKAS-accredited body 0026, with a scope statement that matches the services under review.
    Witnessed by
    Your security reviewer, without contacting MaxIron
  2. V2

    Framework and partner listings

    Passes when
    Supplier 721548 appears on the Digital Marketplace G-Cloud 14 listing, and company 8294 appears in the IBM Partner Plus directory at Gold tier.
    Witnessed by
    Your procurement lead
  3. V3

    Security contact and disclosure path

    Passes when
    A message to security@maxiron.com receives same-business-day acknowledgement during UK business hours. PGP key is supplied on request for encrypted vulnerability disclosure. Coordinated disclosure: acknowledgement within one business day, status update within five business days, researcher credit in any subsequent advisory if requested.
    Witnessed by
    Your security operations or vulnerability management lead
  4. V4

    Sub-processor notification commitment

    Passes when
    Customers under a DPA receive notification of any sub-processor addition or material change at least 30 days in advance, unless an urgent security or operational need requires faster action. The published list matches the processing described in the DPA.
    Witnessed by
    Your data protection officer

Sub-processors

Third parties that process customer or MaxIron-internal data

Reviewed quarterly and updated when material changes occur. Customers under a DPA receive notification of any addition or material change at least 30 days in advance unless an urgent security or operational need requires faster action.

Ref Sub-processorPurposeRegionCertifications
P1 Amazon Web Services (AWS)Cloud platform for customer Maximo environments and MaxIron internal serviceseu-west-1 Ireland, eu-west-2 LondonISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, PCI DSS
P2 Microsoft AzureCloud platform for customer Maximo environmentsUK South, North EuropeISO 27001, ISO 27017, ISO 27018, SOC 1/2/3
P3 Oracle Cloud Infrastructure (OCI)Cloud platform for customer Maximo environmentsUK South, EU FrankfurtISO 27001, ISO 27017, ISO 27018, SOC 1/2/3
P4 Microsoft 365MaxIron internal email, collaboration, identity (Entra ID)EUISO 27001, SOC 1/2
P5 Microsoft IntuneEndpoint MDM, EDR and device compliance enforcementEUISO 27001, SOC 1/2
P6 CloudflareCDN, edge proxy and DDoS protection for maxiron.com and the MaxIron PortalGlobal edgeISO 27001, ISO 27018, SOC 2
P7 ResendTransactional email delivery for contact and quote formsEUSOC 2
P8 Plausible AnalyticsCookie-less, privacy-first website analyticsEU (Germany)GDPR-aligned, no PII collected
P9 Cal.comBooking widget for the free 30-minute Maximo Health Check reviewEUISO 27001, GDPR-aligned

Plausible Analytics and Cal.com are described as GDPR-aligned on this page, not as certified to ISO/IEC 27001 by MaxIron. Cloud infrastructure providers hold SOC 2 Type II and ISO 27001 certifications.

Quarterly Trust Report

Current Trust Report and Statement of Applicability

Shared on request · dedicated landing page in progress

  • Changes to the sub-processor list in the quarter
  • Security incidents that affected any customer environment, or a clear none
  • Policy updates in the period
  • Statement of Applicability under NDA for customers who need Annex A mapping

The dedicated Trust Report landing page is being built. Until it ships, the current edition is shared on request to security@maxiron.com or office@maxiron.com. General queries: office@maxiron.com.

Put the open diligence question to security@maxiron.com.

Monitored during UK business hours, with a same-business-day acknowledgement target. Bring the questionnaire, the NDA status and the date your panel needs a written answer.

Useful to attach

  • The questionnaire or control set you are scoring against
  • Whether an NDA is already signed for the Statement of Applicability
  • The environments and data categories in scope for the engagement
  • The decision date your panel is working to