Last week, we reached an important milestone at DefendDomain: we achieved our ISO/IEC 27001:2022 certification. It's a great recognition of the work our team puts into protecting our customers, managing risk and keeping security at the heart of how we operate.
We formed the company on 18 September 2025. The external audit landed 357 days later, eight days short of our first birthday. ISO 27001 was one of the goals we wrote down on day one, and getting there inside a year is something the whole team is proud of. Before the story, though, it is worth explaining what the certificate actually means, because it is easy to wave a logo around and never say what sits behind it.
What ISO 27001 is
ISO/IEC 27001 is the international standard for information security management. It is published jointly by the International Organization for Standardization and the International Electrotechnical Commission, and the 2022 edition is the current version. It is not a list of products to buy or a set of boxes to tick. It provides a framework for running an Information Security Management System, an ISMS: understanding your context and who depends on you, identifying and assessing your risks, choosing the controls that treat them, making leadership accountable, measuring whether the controls work, and improving over time.
Certification means an independent, accredited body has examined all of that and confirmed it is real. Not that the documents exist, but that the system operates. The auditor samples evidence across the whole standard, from access reviews and supplier assessments to backup restore tests and incident records, and then comes back every year to check it is still true. The certificate can be verified by anyone, which is why security and procurement teams ask for it.
ISO 27001 does not certify that you are secure today. It certifies that you have a working system for staying secure as your business, your people and your threats change.
Why it matters for a company like ours
DefendDomain exists to protect other companies from impersonation. To do that, our customers give us the names of the brands and domains they care about, and we collect evidence about the people attacking them. That is sensitive information, and our customers only benefit from what we do if they can trust how we handle it.
Saying “we take security seriously” is free. Every vendor says it. ISO 27001 is the way to prove it in a language that security teams, auditors and regulators already speak, and it is increasingly the baseline a security supplier is expected to meet before a conversation can even begin. We wanted to be able to answer that question with a certificate number rather than a paragraph of reassurance.
Built from the ground up
We did not inherit a set of policies from a parent company, and we did not buy a template and change the logo. When you start a company from nothing, you get one chance to decide how it is going to run, and we decided that the management system would be designed around the way we actually work rather than bolted on afterwards.
In practice that means the controls the auditor sampled are the same ones we would have wanted anyway. Every change to production goes through a gated pull request with automated and human review. Production credentials never touch a developer laptop. Access follows least privilege and is protected by multi-factor authentication everywhere. Backups are encrypted and we run restore drills to prove they work. Internal audits are scheduled across the year with named owners, and leadership reviews the whole system on a fixed cadence. None of that was written for the auditor. It is how we ship software.
The ISMS is a core part of how we run the business, not a folder that gets dusted off once a year. Risk reviews feed the product roadmap. Supplier assessments decide which services we build on. Incident learning changes the way we work. The certificate is the external confirmation of a system we rely on internally every week.
Zero major nonconformities. Zero minor nonconformities. Twenty-nine positive observations. The auditor's recommendation was a straight pass, confirmed by the certification body's technical review the following day.
Under a year
Most companies come to ISO 27001 several years in, usually because a customer or a tender forced the issue. We put it on the list at incorporation, alongside building the product and winning the first customers, because we knew the day would come when a serious buyer asked for it and we did not want to be starting from scratch when they did.
Doing it in the first year, while also building a multi-layer detection platform, an automated takedown pipeline and a customer base, took real discipline from a small team. There were weeks when writing a supplier assessment or running a restore drill was not the most exciting thing on the board. It got done anyway. Watching an independent auditor sample that work and find nothing to correct was a genuinely rewarding moment for everyone involved, and a good early answer to the question of what kind of company we want to be.
What this means for customers
The certificate covers the provision of digital risk management and security services to protect customer assets, information and online presence. That is the whole of what we do. The current certificate runs until September 2027 and is renewed at each annual external audit, so the standard we were held to last week is the standard we will be held to every year.
If you are evaluating DefendDomain and want the detail behind the badge, our security page sets out how we host and encrypt data, how access is controlled, how environments are separated and how we test ourselves. If your security team needs more, we are happy to walk them through the ISMS directly.

David Batey is co-founder and CTO of DefendDomain and owns the company's Information Security Management System. Certificate 535732026 was issued by Citation ISO Certification Limited on 10 September 2026 and can be verified through the IRQAO register.
