2026 Q4
VERBİS obligation assessment and registration
Assessing the registration obligation, data inventory, retention and destruction policy, registration if required
%55
Compliance
We do not hold a certificate for any standard today, and we do not hide it. Below we publish the quarter in which we aim to be ready for each standard and how far preparation has progressed. When an item is completed, this page is updated with the independent audit details.
Write to usNone of these items is a completed certification. The percentage is the estimated progress of internal preparation; quarters are targets and may change.
2026 Q4
Assessing the registration obligation, data inventory, retention and destruction policy, registration if required
%55
2027 Q1
Quality management system, roadmap
%30
2027 Q1
Assessment of risk classification and transparency obligations
%40
2027 Q2
Information security management system, roadmap
%35
2027 Q3
Privacy information management, roadmap
%20
2027 Q4
AI management system, roadmap
%15
2027 Q4
Observation period and independent audit, roadmap
%10
The table explains the scope of each standard and what it changes for you. The status column shows today's reality.
| Standard | Scope | What it means for you | Status today |
|---|---|---|---|
| VERBİS obligation assessment and registration | Assessing the Data Controllers Registry obligation, a personal data inventory and registration if required | An official record of which data we process, why and for how long | Roadmap |
| ISO 9001 | Quality management system | Defined and measured support, release and change processes | Roadmap |
| EU AI Act (2024/1689) | Risk-based rules for AI systems | Documented risk class and transparency obligations for the assistants | Readiness assessment |
| ISO/IEC 27001 | Information security management system | Independent audit of risk assessment, access, incident management and supplier controls | Roadmap |
| ISO/IEC 27701 | Privacy information management on top of 27001 | Audit of controls in both the controller and processor roles | Roadmap |
| ISO/IEC 42001 | AI management system | Responsible development and monitoring of AI features | Roadmap |
| SOC 2 Type II | Effectiveness of security and availability controls over a period | An auditor's report that the controls actually worked for months | Roadmap |
None. Every item on this page is a roadmap item. When we obtain a certificate, we will announce it here with the certification body and scope.
The estimated progress of internal preparation: writing policies and procedures, risk assessment, implementing controls and collecting evidence. They do not reflect an independent audit result.
Yes. We answer your questionnaire in writing based on the actual practices on our security and data processing pages; if we do not yet apply a control, we say so.
A Type II report audits that controls worked throughout an observation period lasting months. The controls within the 27001 scope need to be in place first, then the observation period can start.
Security, KVKK and GDPR, subprocessors, backups and the compliance roadmap in one place.
Infrastructure, tenant isolation, encryption, access control and audit trail.
Data subject rights, how to apply, cross-border transfer and AI processing.
Controller and processor roles, data categories per module and retention.
Target 99.9% availability, maintenance windows, incident communication and support times.
Let us go through the documents and controls your procurement process asks for together.
Write to us