CUBE maintains structured, version-controlled evidence for its ISO/IEC 27001 information security management system and its ISO 9001 quality management system — kept current so the platform is ready for customer review and third-party audit at any time.
Eight version-controlled evidence artifacts ground every statement on this page. None of them is a score — each is a document or register a reviewer can open.
ISO/IEC 27001:2022 · Clauses 4.1–4.4
Defines the organizational context, interested parties, and the exact boundary of systems in and out of scope — from the API gateway and production database to the CI/CD pipeline and the compliance evidence binders themselves.
93 Annex A controls assessed
Every 2022 Annex A control is individually assessed: 82 applied controls each cite specific evidence, 3 are met through compensating controls, and 8 are excluded with a documented justification — CUBE operates no physical data centers, keeps no paper records, and connects to no industrial control systems.
15 identified risks
Each risk — from credential compromise to vendor concentration — is rated for inherent and residual likelihood and impact, assigned a named owner, and tied to a documented treatment plan and control references.
19 information assets
Every code repository, database, secrets vault, audit log store, CI/CD pipeline, sub-processor, and endpoint device in scope is classified and mapped to the Annex A controls that protect it.
6 topic-specific policies
Access control, business continuity, cryptography, incident response, information security, and supplier management — each policy states its scope, owner, and review cadence.
Corrective and preventive actions
Findings from internal audits and incidents are logged with a root cause, a corrective action, a preventive action, and a verification method — a finding is not closed until its effectiveness is checked.
5 internal audits scheduled for 2026
A quarterly program covering document control, the software delivery lifecycle, customer onboarding and support, and incident and vendor management, each with a named lead auditor and stated audit criteria.
40 US Core profiles tracked
CUBE publishes a public FHIR R4 capability statement and documents its coverage of the HL7 US Core 6.1.0 implementation guide and USCDI v3, profile by profile — active, in preview, or planned — rather than as a single index number. No conformance is declared.
When an internal audit or an incident surfaces a gap, it goes into the CAPA register with an owner, a target date, and a verification method. The register currently tracks 4 items: 1 closed after its effectiveness was verified, and 3 still open or in progress — nothing is marked closed until it has been checked.
CUBE is aligned with ISO/IEC 27001 and ISO 9001, and certified under neither. Controls and evidence are maintained continuously, so the platform is ready for customer review and third-party audit today.
An independent pre-evaluation against both frameworks — document CII-PRE-2026-001 v1.0, methodology consistent with ISO 19011 — was completed 25 February 2026 by CIIESOST. It found a level of structural readiness that may allow CUBE to proceed to a formal certification audit under an accredited scheme. It is not certification, not accreditation, and not a conformity decision under ISO/IEC 17021, authorizes no ISO logo or certification-mark use, was conducted on a sampling basis with no independent penetration testing, and did not evaluate all 93 Annex A controls — a separate fact from the Statement of Applicability above, which is CUBE's own internally-produced assessment of all 93.
A point-in-time independent finding, dated 25 February 2026. Its six-month informational validity has run; the evidence it examined has been maintained continuously since, it remains available for review under NDA, and a renewed report is planned.
Certification is approached one framework at a time, including any infrastructure change it requires.
View certification status for every frameworkThis page describes maintained evidence, not a certification.
The artifacts above reflect CUBE's internal control mapping, risk management, and audit-readiness posture. They are not a substitute for a third-party audit and do not by themselves constitute ISO 27001 or ISO 9001 certification. Certification is a separate stage, taken one named framework at a time.