Independently Audited Quality & Information Security

Security and Compliance

ISO-Certified Quality and Information Security Management

MicroTelecom's ISO 9001:2015 and ISO/IEC 27001:2022 certifications provide independent evidence that our quality and information-security management systems are formally documented, actively operated, regularly reviewed and externally audited.

The certified management systems cover the processes used to design, develop, secure and deliver business-critical technology within the stated certification scopes.

Current Certifications

ISO 9001:2015

Quality Management System

Valid through

ISO/IEC 27001:2022

Information Security Management System

Valid through

Current certificates and supporting documentation are available to customers and prospective customers upon request.

Certification Details

Our Certified Management Systems

Each certification has a defined scope covering the MicroTelecom activities assessed through the certification process.

Certified

ISO 9001:2015

Quality Management System

Valid through

Certified Scope

Design, development and deployment of cloud-based and on-premises business systems, including point of sale, inventory management, order fulfillment, e-commerce, service desk, payment solutions, mobile business applications and self-checkout solutions, for small businesses and enterprises.

Certified

ISO/IEC 27001:2022

Information Security Management System

Valid through

Certified Scope

Technology and consulting services, including point-of-sale platforms, payment integrations, AI/ML services and cloud-hosted applications.

Copies of current certification documents can be provided for procurement, vendor review and due-diligence purposes upon request.

Quality Management

Quality Policy Statement

Our Quality Policy defines the commitments that guide MicroTelecom's Quality Management System and our approach to customer requirements, delivery and continual improvement.

MicroTelecom is committed to delivering innovative and high-quality solutions that meet or exceed the expectations of our customers in the retail, wholesale, and commerce industries. We align our operations with market demands and customer requirements, ensuring that every project adheres to defined scope, budget, and timelines.

Quality is a shared responsibility across all levels of our organization. Through compliance with applicable standards and regulations, and by fostering a culture of continual improvement, we strive to enhance customer satisfaction and operational excellence. This policy reflects our dedication to supporting our strategic goals and ensuring sustainable growth.

Approved by: Executive Compliance Officer (Top Management)
Effective:
Version: Rev. 02
Applies to: MicroTelecom Quality Management System

External Certification

Certification and External Audits

MicroTelecom's management systems are examined through formal independent certification audits.

Maintaining certification requires documented processes, operational evidence, internal review, corrective action and continual improvement. External audits assess whether the management systems are implemented and operating within their certified scopes.

Certification provides customers and procurement teams with independent evidence that defined quality and information-security management practices are applied across the activities included in those scopes.

Quality Management

What ISO 9001:2015 Covers

ISO 9001 provides a framework for consistently meeting customer and applicable requirements, managing processes, measuring performance and continually improving how an organization operates.

Customer Focus

Understanding requirements and using feedback to improve products, services and delivery.

Controlled Processes

Defined responsibilities, documented workflows and consistent review throughout the service lifecycle.

Performance & Accountability

Objectives, measurements, internal audits and management review help keep delivery visible and accountable.

Continual Improvement

Issues, risks and opportunities are reviewed so corrective action and practical improvements can follow.

Information Security

What ISO/IEC 27001:2022 Covers

ISO/IEC 27001 defines requirements for an Information Security Management System. It provides a risk-based framework for protecting information through coordinated policies, processes, people and technology.

The management system includes processes for assessing information-security risks, selecting appropriate treatments, monitoring effectiveness and continual improvement.

Confidentiality

Information is accessible only to authorized people and systems.

Integrity

Information remains accurate, complete and protected from unauthorized change.

Availability

Authorized users can access information and services when required.

  • Information-security risk assessment and treatment
  • Access control and identity-management practices
  • Supplier, cloud-service and technology risk management
  • Incident preparation, response and improvement
  • Business continuity and operational resilience considerations

Combined Management Systems

Quality and Information Security Working Together

The two management systems address complementary areas of service delivery: process quality and information-security risk management.

Area ISO 9001:2015 ISO/IEC 27001:2022 Operational Relevance
Primary focus Quality and consistent delivery Information-security risk management Documented quality controls and security risk management
Management approach Process control and improvement Risk assessment and treatment Decisions supported by defined processes and evidence
Review and improvement Objectives, measurement and corrective action Security monitoring, review and improvement Governance that continues after initial implementation

Enterprise Production Experience

Tier-1 Production Environments

MicroTelecom platforms operate in production within Tier-1 enterprise service-provider environments across multiple markets. These environments include demanding security, privacy, availability, integration and operational requirements.

Business-Critical Operations

Our systems support point of sale, payments, service delivery and other customer-facing operations.

Enterprise Review

Tier-1 deployments can include technical, security, procurement, integration and operational review requirements.

Global Deployment

Production environments operate across multiple markets with regional privacy, security and operational requirements.

Ongoing Review

Internal reviews, vulnerability management, security testing and management-system audits continue as part of ongoing operations after deployment.

Privacy & Payment Security

Privacy and Payment Security in Practice

Our certified management systems provide a governance foundation for the privacy, data-protection and payment-security practices applicable to the MicroTelecom platform and our role in customer environments.

GDPR

We apply privacy and security practices relevant to our platform and role when supporting environments subject to European data-protection requirements, while customers remain responsible for their own regulatory obligations.

Data Protection

Our operating processes consider applicable data-protection requirements in jurisdictions where MicroTelecom systems and services are deployed.

PCI Security Practices

Where applicable, externally accessible in-scope systems undergo recurring vulnerability scanning and remediation processes in accordance with the payment-security requirements applicable to MicroTelecom's component and role.

Security and Privacy Are Shared Responsibilities

MicroTelecom is responsible for the security and privacy controls applicable to our platform component. Customers, payment providers and other integrated service providers remain responsible for their respective systems, configurations, business processes and use of data.

Operational Application

Application of the Certified Management Systems

Certification gives customers and procurement teams independent evidence that MicroTelecom maintains formal management systems within the stated scopes.

Structured Delivery

Projects and services are supported by defined processes, responsibilities and review points.

Risk-Based Decisions

Quality and information-security risks are identified, assessed and addressed through formal processes.

Enterprise Due Diligence

Certification documents can support vendor reviews, procurement questionnaires and governance discussions.

Continual Improvement

Audits, measurement, management review and corrective action support ongoing improvement.

Frequently Asked Questions

Certification FAQs

What does ISO certification mean?

It means an independent certification process has assessed MicroTelecom's relevant management system against the requirements of the named standard and certified the activities within the stated scope.

Are individual MicroTelecom products ISO certified?

These are management-system certifications. They apply to MicroTelecom and the activities stated in each certification scope rather than certifying an individual software product.

Does ISO/IEC 27001 eliminate information-security risk?

No management system can eliminate every risk. ISO/IEC 27001 establishes a systematic process for identifying, treating, monitoring and continually improving the management of information-security risks.

How do the ISO standards support privacy and payment security?

The certified management systems establish documented governance, risk-management, review and improvement processes that support privacy and payment-security practices applicable to our platform and operations.

Where can I find MicroTelecom's Quality Policy?

MicroTelecom's current Quality Policy Statement is published on this page and forms part of our Quality Management System.

How can I request certification documents?

Contact MicroTelecom with your company details and due-diligence requirements. We can provide appropriate current certification documents and discuss questions relevant to your proposed solution.

Certification Documents and Security Information

Contact us to request copies of our current certification documents or discuss security, quality and compliance requirements for your deployment.