Trust Center

Security claims should be backed by evidence.

Dewtech is building and operating a documented information security management program covering risk, secure development, access, incidents, suppliers and AI/agent security. Public claims are intentionally limited to what can be supported by current evidence.

security@dewtech.techISO/IEC 27001 certification not yet claimed

Security governance

Documented scope, risk assessment methodology, treatment planning, control applicability and management review are being formalized within the Dewtech ISMS.

Secure development

Engineering practices emphasize explicit requirements, review, deterministic validation, supply-chain controls and traceable releases.

Access control

Least privilege, MFA, privileged-access review, credential isolation and service-account governance are core control objectives.

Vulnerability management

Dewtech maintains risk-based vulnerability discovery, triage, remediation and exception workflows for systems under its control.

Incident response

Security events are intended to follow defined triage, containment, evidence preservation, recovery and post-incident review procedures.

Responsible AI

AI and agentic systems are treated as untrusted decision components around which deterministic authorization, sandboxing, human oversight and audit controls are built.

Assurance roadmap

Trust is a program, not a badge.

Current

ISMS scope, risk methodology, risk register, treatment planning, Statement of Applicability preparation and evidence mapping.

Operating controls

Policies, access reviews, vulnerability evidence, backups, incident exercises, supplier reviews and secure development records.

Independent assurance

Internal audit, corrective actions and management review before external certification activities.

Certification

Dewtech will only represent itself as ISO/IEC 27001 certified after a valid certificate is issued for a clearly defined scope.

Vulnerability disclosure

If you believe you have identified a security issue affecting a Dewtech-controlled system, send sufficient technical detail to security@dewtech.tech. Do not access customer data, disrupt services or perform destructive testing without explicit authorization.

Privacy & data handling

Privacy, retention and customer-data handling requirements are governed by applicable agreements, legal obligations and Dewtech internal security processes. Questions can be directed to privacy@dewtech.tech.

Security & assurance

Need security information for procurement, due diligence or a technical review?

Contact Dewtech with the context of your request. We will distinguish implemented controls, planned improvements and formal certifications rather than collapsing them into a generic compliance claim.

Contact Security