- One certification, ISO/IEC 27001:2022 (BSI). Production's badge row also shows ISO 27017, ISO 27018, ISO 9001, SOC 1, SOC 2, SOC 3, PCI DSS Level 1 and CSA, while its own text says "SOC 2 aligned operations". None of those badges appears here as a Codekeeper certification until the team confirms them.
- No absolutes. "Security isn't something we add, it's how we're built", "24/7 monitoring", "without a security incident" for a decade and "Even our own engineers cannot bypass these controls" are left out.
- A page-specific path for reviewers. The line under the buttons jumps to the documents and the request form. The hero keeps the site's two standard buttons.
- The hero visual is a summary of the controls set out on this page, not a certificate image, so it can't be mistaken for the certificate itself.
We hold your code to a certified standard.
Codekeeper is certified to ISO/IEC 27001:2022, audited by BSI. Here's how we protect your deposits, how Agentic Verification keeps your code in our environment, and which documents you can request for your review.
Reviewing us as a supplier? Request our security documents
- ISO/IEC 27001:2022 certified
- AES-256 encryption at rest
- Founded 2014
Trusted by 3,500+ teams, from regulated enterprises to fast-growing software vendors
Certification
Certified to ISO/IEC 27001:2022.
Our information security management system is certified to ISO/IEC 27001:2022 and audited every year by BSI. We identify and treat information security risks the way the standard requires.
ISO/IEC 27001:2022
Certified, with an annual certification audit by BSI. The certificate and an ISMS summary are available on request.
Certified data centre partners
We don't run our own data centres. Our hosting partners' data centres hold ISO 27001 and SOC 2 certifications.
GDPR and a DPA
We handle personal data in line with GDPR, and our data processing agreement is available to customers on request.
- Encryption: production says both "AES-256" and "AES-256/512". The page says AES-256. Production's "end-to-end encryption" heading describes encryption at rest and in transit, so that's what the page says.
- Multi-factor authentication: production says "All accounts are protected with MFA" and the FAQ says 2FA is required for all users, but the encryption answer says "optional multi-factor authentication". The page says MFA without "all" or "required" until one answer is confirmed.
- Access to deposits: the production FAQ says "no one at Codekeeper has access to your escrowed materials"; the Trust Center says we access deposited code only for release or verification. The page uses the Trust Center version.
- Incident response: "typically within 24 hours" is production's figure and is flagged until security confirms it. Production's "notification timelines that meet GDPR's 72-hour requirement" is left out; the page uses production's other wording, "without undue delay". Legal should confirm which commitment applies.
- Testing: plans are "tested at planned intervals" (production's summary). Penetration testing is not claimed: the production FAQ says "We do not currently conduct penetration testing", although its summary lists "third-party audits". Production's "cyber insurance" line is also left out, to keep "insurance" off the site.
Controls
How we protect your deposits.
The controls behind the certificate, grouped the way security questionnaires ask about them.
Data protection
- AES-256 encryption at rest
- TLS for data in transit
- Encryption keys managed through a defined lifecycle, including rotation
- Deposit operations and access attempts logged
Access control
- Multi-factor authentication
- Least-privilege access, reviewed every quarter
- No access to deposited code except for a release or a verification, and every access is logged
- Release conditions verified before anything is released
Infrastructure
- Hosted with major cloud providers
- Partner data centres with ISO 27001 and SOC 2 certifications
- Firewalls, intrusion detection and network segmentation between environments
- DDoS mitigation and continuous vulnerability scanning
People and governance
- Background checks and confidentiality agreements for team members
- Security awareness training at onboarding and every year
- A dedicated information security team
- Regular risk assessments and vendor security reviews
Incidents and continuity
- Incidents handled as soon as they're identified, typically within 24 hours
- Affected customers informed without undue delay
- Incident response, business continuity and disaster recovery plans, tested at planned intervals
- Automated, encrypted backups of our databases
Privacy
- Personal data handled in line with GDPR
- A data processing agreement on request
- Customer data deleted on request, from active systems and backups
- Data kept for the agreed retention period, then erased
Agentic Verification
Your code stays in our environment.
Agentic Verification runs on Codekeeper's own models. No third-party AI sees your deposit, and each rebuild runs in its own sealed sandbox.
- Codekeeper's own models, with no third-party AI
- Code doesn't leave Codekeeper's environment
- A sealed sandbox for each run, cut off from production, development and the open internet
- Self-serve runs: the depositor can add or remove materials at any point
- The deployable copy is held by the depositor; the customer gains access on a release event
Documents
Documents for your review.
Request what your security review or supplier onboarding needs. General documents are shared without an NDA. Confidential security documents are shared under NDA.
Request access
Request security documents.
Tell us what your review needs. We'll check the request and share the documents, under NDA where they're confidential.
- The ISO 27001 certificate, ISMS summary and security policies
- Company, tax and banking details for supplier onboarding
- Questions answered by our security team
Sample evidence pack
See what your auditor would receive.
An anonymised set of outputs from a real Agentic Verification run, so you can judge the evidence before you talk to us.
- Recoverability Certificate
- Run report
- SBOM and Exit workbook excerpts
Questions
Security questions.
Which certifications does Codekeeper hold?
Codekeeper is certified to ISO/IEC 27001:2022, audited by BSI. The data centres our hosting partners run hold ISO 27001 and SOC 2 certifications.
Where is my source code stored?
Encrypted, with major cloud providers whose data centres hold ISO 27001 and SOC 2 certifications. We don't operate our own data centres. The Security Assurance Report, available on request, describes our network environment in more detail.
Who at Codekeeper can access my deposit?
We don't access deposited code except for a release or a verification, and every access is logged. Access to sensitive information is granted on a need-to-know, least-privilege basis and reviewed regularly.
Does Agentic Verification send my code to an AI provider?
No. Agentic Verification runs on Codekeeper's own models, and your code stays in our environment. Each run gets its own sealed sandbox, cut off from production, development and the open internet.
How do you handle a security incident?
We follow a documented incident response plan: reporting, impact assessment, containment, eradication and root cause analysis. Incidents are handled as soon as they're identified, typically within 24 hours, and affected customers are informed without undue delay. After each incident we review the response and update the plan.
Will you sign a data processing agreement?
Yes. Our DPA sets out how we handle and protect customer data in line with GDPR, including our technical and organisational measures. It's available on request. Data processing agreement
Can you delete our data?
Yes. Customer data is deleted on request, from active systems and from backups. When a service ends, data is returned or deleted in line with the agreement. Request deletion
Do we need an NDA to see your documents?
Only for confidential security documents. General documents are shared without one. Request documents
Who can I contact with a security or privacy question?
For security and compliance questions, email contact@codekeeper.co. For privacy questions, email privacy@codekeeper.co.
Protection you can check, for the software you can't lose.
See how Codekeeper would hold, verify and recover your applications, and what it would show your reviewers.