Skip to content

Security program

Compliance

WebCastle’s current position on security certifications, attestations and framework alignment — stated plainly, without implying certifications we do not hold.

Reviewed 12 August 2026

Certifications & attestations

WebCastle does not currently hold security certifications

WebCastle has not completed an ISO 27001 certification, a SOC 2 examination, or an equivalent independent attestation, and does not imply otherwise anywhere on this site. What WebCastle does have is the substance those frameworks assess: encryption in transit and at rest, multi-factor authentication on administrative access, separated environments, reviewed changes to production, restricted production access and segregated customer data — each described control by control on the practice pages, with its current status stated openly.

What to do if your process expects a certificate

A certificate is evidence of controls, not a substitute for them. If your review normally accepts a report in place of direct assessment, WebCastle can complete your security questionnaire, provide written descriptions of the specific controls you need to evidence, and discuss architecture under NDA. Most reviews that reach this page are completed from the published control detail plus one follow-up conversation.

See the control detail

Frameworks & regulations

WebCastle's position on the frameworks customers ask about most. Listing a framework here indicates alignment work or evaluation — never certification.

ISO/IEC 27001

ISO/IEC

Under Evaluation

WebCastle is evaluating ISO/IEC 27001 as a target framework for its information security management system. The current focus is on establishing the governance, documentation and control evidence that certification would require. No certification audit has been scheduled.

Alignment or evaluation only. This is not a certification.

SOC 2

AICPA

Under Evaluation

WebCastle is assessing whether a SOC 2 examination is appropriate given its customer base and the services it operates. No readiness assessment, Type I or Type II examination has been performed.

Alignment or evaluation only. This is not a certification.

NIST Cybersecurity Framework

NIST

In practice

WebCastle uses the NIST CSF functions — Identify, Protect, Detect, Respond, Recover — as an informal structure for organising its security program and identifying gaps. This is an internal planning aid; the framework carries no certification.

Alignment or evaluation only. This is not a certification.

CIS Controls

Center for Internet Security

In practice

WebCastle references the CIS Controls when prioritising security improvements, particularly around asset and account management. Alignment is partial and is not independently assessed.

Alignment or evaluation only. This is not a certification.

GDPR

EU regulation

In practice

GDPR is a regulation, not a certification — no organisation can be "GDPR certified", and WebCastle makes no blanket compliance claim. Where WebCastle processes personal data on behalf of a customer, it acts as a processor and the customer’s agreement governs the specific obligations. WebCastle is formalizing the supporting documentation, including its subprocessor register and data handling records.

Alignment or evaluation only. This is not a certification.

PCI DSS

PCI SSC

Not Applicable

WebCastle does not store, process or transmit cardholder data on its own infrastructure. Where a customer project requires payments, it is integrated with a PCI DSS compliant payment provider so that card data is handled by that provider rather than by WebCastle.

Alignment or evaluation only. This is not a certification.

How to read this page

Security certification is often used as shorthand for security maturity. The two are related but not the same, and conflating them creates risk for both sides of a procurement conversation. This page separates them deliberately.

A framework listed as "Under Evaluation" means WebCastle is assessing whether to pursue it. "Developing" means WebCastle references the framework when organising its own controls, without any external assessment. Neither status implies certification, an audit in progress, or a completed readiness assessment.

If your review requires evidence of a specific control rather than a certificate, the security practice pages describe each control and its current maturity, and the security team can discuss specifics under NDA.

What WebCastle can provide today

In the absence of a certification report, these are the artefacts WebCastle can supply during a security review.

  • Completed security questionnaires

    WebCastle completes customer security questionnaires, including SIG-style and bespoke formats, using the same conservative positions published here.

  • Written control descriptions

    Detailed descriptions of a specific control area, prepared for your review team and consistent with the practice pages on this site.

  • Non-disclosure agreements

    WebCastle will sign a customer NDA where a review requires discussing architecture or controls in more detail than is appropriate to publish.

  • Named security contact

    A direct route to the people accountable for security at WebCastle, rather than a generic support queue.

  • Subprocessor information

    The third parties that may process customer data for a given engagement, together with their role and region.

  • Contractual security commitments

    Security and data protection terms are agreed within the individual customer contract, where they carry legal weight.

How WebCastle is approaching compliance

A deliberate sequence: build the controls first, document them, then pursue external validation if customer requirements justify it.

  1. Establish the baseline

    In progress

    Document what WebCastle already does across access control, application security, infrastructure, data protection and incident response. This Trust Center is the visible output of that work.

  2. Close identified gaps

    In progress

    Address the areas that review has surfaced — formal access reviews, a written policy set, structured vendor oversight and a documented incident response plan.

  3. Approve the policy set

    Planned

    Take the drafted policies through internal review and management approval so they become governing documents with named owners and review dates.

  4. Operate and evidence

    Planned

    Run the controls for long enough to generate the evidence any external assessment would examine, including access review records and incident logs.

  5. Evaluate external assessment

    Under evaluation

    Decide, based on customer requirements and the maturity reached, whether to pursue ISO/IEC 27001, SOC 2 or another framework. WebCastle has not committed to a certification or a date.