Security governance
Documented scope, risk assessment methodology, treatment planning, control applicability and management review are being formalized within the Dewtech ISMS.
Trust Center
Dewtech is building and operating a documented information security management program covering risk, secure development, access, incidents, suppliers and AI/agent security. Public claims are intentionally limited to what can be supported by current evidence.
Documented scope, risk assessment methodology, treatment planning, control applicability and management review are being formalized within the Dewtech ISMS.
Engineering practices emphasize explicit requirements, review, deterministic validation, supply-chain controls and traceable releases.
Least privilege, MFA, privileged-access review, credential isolation and service-account governance are core control objectives.
Dewtech maintains risk-based vulnerability discovery, triage, remediation and exception workflows for systems under its control.
Security events are intended to follow defined triage, containment, evidence preservation, recovery and post-incident review procedures.
AI and agentic systems are treated as untrusted decision components around which deterministic authorization, sandboxing, human oversight and audit controls are built.
Assurance roadmap
ISMS scope, risk methodology, risk register, treatment planning, Statement of Applicability preparation and evidence mapping.
Policies, access reviews, vulnerability evidence, backups, incident exercises, supplier reviews and secure development records.
Internal audit, corrective actions and management review before external certification activities.
Dewtech will only represent itself as ISO/IEC 27001 certified after a valid certificate is issued for a clearly defined scope.
If you believe you have identified a security issue affecting a Dewtech-controlled system, send sufficient technical detail to security@dewtech.tech. Do not access customer data, disrupt services or perform destructive testing without explicit authorization.
Privacy, retention and customer-data handling requirements are governed by applicable agreements, legal obligations and Dewtech internal security processes. Questions can be directed to privacy@dewtech.tech.
Security & assurance
Contact Dewtech with the context of your request. We will distinguish implemented controls, planned improvements and formal certifications rather than collapsing them into a generic compliance claim.
Contact Security