DeskOS is ISO/IEC 27001:2022 certified.
Our information security management system has been audited by an external registrar and certified to ISO/IEC 27001:2022. The certificate is below to download and to verify. Our penetration test and disaster recovery reports are a request away.
- ISO/IEC 27001:2022 certified
- Externally audited, not self assessed
- Valid to 21 September 2029
Certificate of registration
Providing software development and SaaS communication platform services. Audited and issued by Magnitude Management Services Pvt. Ltd., and listed on the registrar’s own page so you can check it without taking our word for it.
- Certificate
- 26MEQXD44
- Issued to
- Tech Dreams Private Limited
- Registrar
- Magnitude Management Services Pvt. Ltd.
- Valid to
- 21 September 2029
The three documents a security review asks for.
One downloads here. Two go to a named reviewer after a person has read the request, which is the only responsible way to hand over a report that describes how to attack a system.
- Public
ISO/IEC 27001:2022 certificate
The certificate of registration for our information security management system, issued after an external audit of how we run, staff and review security.
- The certified scope, in the registrar’s words
- Certificate number, issue date and expiry
- The registrar and its accreditation
- The surveillance audit dates the certificate depends on
Download PDFCertificate 26MEQXD44. Valid to 21 September 2029.
- On request
Penetration test report
The findings from our vulnerability assessment and penetration testing, with what was found, what severity it was rated and what we did about it.
- Scope of the test and the methodology behind it
- Findings by severity, with our remediation against each one
- Retest results for anything that was fixed
- The tester, the dates and the tooling
Request accessSent under NDA to a named reviewer, usually the same working day.
- On request
Disaster recovery report
How your data is backed up, how quickly it comes back and what we proved by actually restoring it rather than by writing a policy about it.
- Backup schedule, retention and where copies are held
- Recovery point and recovery time objectives
- The restore test, when it was run and what it measured
- Failover and the order things come back in
Request accessSent under NDA to a named reviewer, usually the same working day.
What the certificate looks like on an ordinary Tuesday.
A certificate says the system is run properly. These are the parts of it you can check yourself, in your own account, on the day you sign.
Your data
- Every operator is a separate tenant, scoped by organisation on every query
- Encrypted in transit with TLS, and at rest on disk and in backups
- Card details never touch our servers: payments go through Razorpay or Stripe
- Exports of your own data on request, in formats your accountant can open
- Data removed on request, subject to the tax retention your own law imposes
Who can see it
- Permission codes on every admin screen and every admin endpoint
- Staff access is per location, so a centre manager sees their own centre
- Financial figures are gated separately from the rest of the record
- Two factor authentication on our own internal administration
- Access for our team is granted for a reason and removed when it ends
Keeping it running
- Backups taken on a schedule and restores tested rather than assumed
- Recovery point and recovery time objectives stated in the DR report
- Alerting on the things that matter, watched by the team who built them
- Changes reviewed before release, with a rollback for every deploy
- A named channel for reporting a vulnerability, answered by engineers
Bring your security questionnaire to the demo. We answer it on the call.
Tell us what your review needs.
The penetration test report, the disaster recovery report, a completed security questionnaire, a DPA, or an answer to one specific question. Say which in the last box and a person replies, usually the same working day.
- Read by a person, not routed into a drip sequence
- We sign your NDA if your side needs one first
- Reporting a vulnerability instead? Email bugbounty@deskos.net or read the bug bounty policy
Request security documents
A work email, so we know who is asking and where the documents are going.
A security review with people on the other end.
DeskOS is built and supported from offices in New Delhi and Delaware. The people who answer a security question are the people who wrote the code it is about.
What happens next
- 1
You ask for what your review needs
The certificate downloads from this page. For the penetration test or disaster recovery report, use the form above.
- 2
A person reads the request
Not a bot and not a drip sequence. We check who is asking, sign an NDA if your side needs one, and send the documents.
- 3
Your security team gets a real answer
If your questionnaire has a question these documents do not answer, we will answer it directly rather than pointing you back at a PDF.
What reviewers ask us
Is DeskOS ISO 27001 certified?
Yes. Our information security management system is certified to ISO/IEC 27001:2022, the current version of the standard, under certificate 26MEQXD44. It was issued on 22 September 2026 by Magnitude Management Services Pvt. Ltd. and is valid to 21 September 2029. The certificate is on this page to download, and the registrar lists it on its own active clients page so you can check it without taking our word for it.
What does the certificate actually cover?
The certified scope is "Providing software development and SaaS communication platform services." against Statement of Applicability version 1.0, dated 15 January 2026. The certificate is issued to Tech Dreams Private Limited, the company that builds and operates DeskOS. We quote the scope rather than paraphrase it, because a scope statement is the part of a certificate people most often stretch.
Who accredited the registrar?
Magnitude Management Services Pvt. Ltd. holds EGAC, ISMS certification, CAB #011805, which sits under the IAF Multilateral Recognition Arrangement. That arrangement is what makes a certificate issued by one accreditation body recognised by the others. If your procurement policy names a specific accreditation body, tell us during the review and we will say plainly whether ours is the one you need.
Can we see your penetration test report?
Yes, on request and under NDA if your side needs one. We do not publish it, because a full penetration test report describes where to look and in what order. Ask through the form on this page and a person sends it, usually the same working day.
What happens to our data if something goes badly wrong?
Backups are taken on a schedule and restores are tested rather than assumed. The disaster recovery report states the backup schedule, the retention, the recovery point and recovery time objectives, and what the last restore test actually measured. It is available on request.
Where is our data held?
Your data is held with our cloud infrastructure provider, and the region is stated in your agreement. If you have a requirement to keep data inside a particular country, raise it before you sign and we will tell you whether we can meet it rather than after.
Do you handle card details?
No. Payments run through Razorpay or Stripe, and card details go from your member to the gateway without passing through DeskOS. We hold the result of the payment, not the instrument.
We found a vulnerability. Where do we send it?
To bugbounty@deskos.net. The reporting policy, what is in scope and what we ask you not to do is on our bug bounty page, linked at the foot of every page on this site. Reports are read by the engineers who can fix them.