
ISO 27001 Certification
ISO 27001 is recognized as the premier information security management system (ISMS) standard worldwide. ISO 27001 also leverages the comprehensive security controls detailed in ISO27002. The basis of this certification is the development and implementation of a security management program, including the development and implementation of an Information Security Management System (ISMS). This widely-recognized and widely-respected international security standard specifies that companies that attain certification also:
Systematically evaluate information security risks, taking into account the impact of security threats and vulnerabilities.
Design and implement a comprehensive suite of information security controls to address security risks.
Implement an overarching audit and compliance management process to ensure that the controls meet our needs on an ongoing basis.


Amazon Web Services
iLost runs on Amazon Web Services (AWS), the largest and most secure infrastructure provider on the planet. We ensure our scalability, high availability and security by implementing the following:
Replication of servers across multiple availability zones.
Regular backups of our database and other key systems.
Restricting and monitoring access to servers of the platform.
Application safety
To protect information that’s available on our website and iLost for Business app, we apply a number of security measures:
- Encryption of all web traffic using modern cryptographic methods (TLS 1.2 and later) and forward secrecy
- Strict Transport Security to prevent downgrade attacks, hijacking etc.
- All passwords are one-way encrypted in the database using bcrypt.
Strict enforcement of role-based ACLs for all endpoints that provide access to sensitive information.
GDPR Compliancy
We only use personal data in accordance with our Privacy Policy and to provide the services we offer. We value privacy, and we’ll do everything we can to protect it. For every new product and enhancement, we’re proactively applying the Data Protection by Design principles.We only use personal data in accordance with our Privacy Policy and to provide the services we offer. We value privacy, and we’ll do everything we can to protect it. For every new product and enhancement, we’re proactively applying the Data Protection by Design principles.
PCI-DSS compliance
Payment Card Industry Data Security Standard (PCI-DSS) is a set of security standards designed to ensure that all companies that accept, process, store or transmit credit card information maintain a secure environment. iLost is committed to maintaining PCI-DSS compliance to protect payment card data.
Secure payment processing through certified payment service providers
No storage of sensitive cardholder data on our systems
Regular security assessments and vulnerability scans
Encrypted transmission of all payment information
