Effective Date: 2026
At tbo., information security is not a future aspiration—it is an operational reality. Our governance framework is built on internationally recognized quality certifications that we already hold (ISO 9001:2015, ISO 17100:2015, ISO 18587:2017, ASTM F3130-18 and CGSB 131.10-2017), all of which incorporate risk-based thinking and documented process controls.
Our Compliance & Certification Roadmap
ISO/IEC 27001
Alignment We are actively evolving our current management system to fully align with the requirements of ISO 27001.
Current status: We already have a strong foundation through our existing certifications, which require risk management and security controls. We are currently maturing our information security-specific controls in preparation for formal certification.
SOC 2 Commitment
Our roadmap includes adoption of the SOC 2 Trust Services Criteria.
Current status: We already implement logical security controls, access management, and data protection measures—all of which are core pillars of a future SOC 2 audit.
____________
Security Measures Already in Place
Unlike organizations that are still in the early stages, we already have the following verifiable processes in place:
● Proactive Risk Management: A dedicated Quality Management team and a tracking platform allow any team member to report risks or opportunities, ensuring that threats are systematically assessed and mitigated.
● Logical Security & Access Control: Access to client information is strictly restricted based on role and business need, managed through centralized systems that control who can access the information.
● Contractual Confidentiality: All employees and contractors sign non-disclosure agreements (NDAs) before beginning any project.
● Data Protection & Privacy: We maintain strict protocols for secure data deletion upon client request and periodic local data purging on devices to minimize the risk of data breaches.
● Reliable Infrastructure: We use industry-leading Translation Management Systems (TMS) that ensure the availability and safeguarding of information. These systems include functionalities designed to support compliance with the European Union’s General Data Protection Regulation (EU GDPR).
____________
Transparency for Client Audits
If your compliance team requires validation of our current controls, we can provide the following under a mutual NDA:
● our risk management system
● security and data disposal reports issued by our IT team
● details of our ISO-based governance frameworku have questions or comments about this policy, please contact us by email at in**@*bo.group.