Trust is earned, so we show our working.
Understanding Zoe Pty Ltd operates an Information Security Management System certified to ISO/IEC 27001:2022 by Prescient Security.
The certification covers our management system, which is how we govern information security. It is not a certification of the app itself. You can check that our certificate is current on the public IAF register at any time.
The certificate
- Certified organisation
- Understanding Zoe Pty Ltd
- Management system
- Information Security Management System
- Standard
- ISO/IEC 27001:2022
- Certification body
- Prescient Security
- Certificate number
- 122887 (Issue 2)
- Original issue date
- 22 July 2025
- Latest revision date
- 14 July 2026
- Valid until
- 21 July 2028
- Accreditation
- International Accreditation Service (IAS), MSCB-267
- Statement of Applicability
- V1.2.0, dated 1 July 2026
The certificate remains valid subject to satisfactory surveillance audits. The most recent surveillance audit completed in July 2026.
Scope of registration
This is the scope exactly as it appears on the certificate.
The scope of the ISO/IEC 27001:2022 certification is limited to the Information Security Management System (ISMS) supporting the Understanding Zoe Pty Ltd. platform. Understanding Zoe is an Australian-owned, cloud-based Software-as-a-Service (SaaS) platform that empowers families, adults, educators, therapists, and other carers of neurodivergent children through personalised, neuroaffirming support. The following departments are in the scope: Information Technology ("IT"), Software Development ("Dev"), Human Resources ("HR"), Information Security ("InfoSec"), Legal, and Finance are within the scope.
Departments within scope
- Information Technology
- Software Development
- Human Resources
- Information Security
- Legal
- Finance
What this means for your data
- Encrypted in transit and at rest.
- Stored in Australia (AWS Sydney).
- Granular permission controls. You decide who sees what.
- Your reports stay yours. Download or delete them anytime.
- Pip chats are private by design.
- Aligned with the Australian Privacy Principles.
Our Privacy Policy sets out how we handle personal information, including the sub-processors we use and where they operate. Read our Privacy Policy.
For security reviewers
Our Trust Centre carries live control status, our sub-processor list, and the documents we share under NDA. That includes the Statement of Applicability and our most recent penetration test summary.
If you need something that is not listed there, including a completed security questionnaire, contact us and a real person will answer.
