TrustSecurity · compliance · accreditations

Trust isn't a marketing line.
It's a certification cycle.

Carriers entrust Solverminds with bookings, schedules, rates, and operational data that doesn't recover well from mishandling. This page is the procurement-grade view of how we hold that responsibility — the certifications, where they apply, and where to send security disclosures.

Certifications in forceactive
ISO/IEC 27001:2013
Re-certified 2022 – 2025
CMMI Level 3 (DEV/3)
First accredited 2015 · Re-accredited 2021
ISO 14064-1:2006
Achieved 2023
SOC 2
Newly attested · 2026

Accreditations

Independently audited. Independently re-audited.

Every certification below is held against an independent auditor with a documented re-certification cycle. Status and cycle dates are as of the current accreditation period.

Information Security Management System

ISO/IEC 27001:2013

Issued by BSI · Re-certified 2022 – 2025

Independently audited information security management system covering policy, access control, cryptographic controls, operations security, supplier relationships, incident management and business continuity. Re-certification cycle runs through 2025.

  • Annual surveillance audits
  • Documented controls across the Annex A objectives
  • Risk assessment + treatment plan reviewed each cycle

Capability Maturity Model Integration

CMMI Level 3 (DEV/3)

Issued by CMMI Institute · First accredited 2015 · Re-accredited 2021

Process maturity for software engineering and product development. Level 3 means processes are characterised for the organisation and proactively managed — not just performed.

  • Standardised engineering and project management processes
  • Defined organisational training
  • Decision analysis and resolution practices in place

Greenhouse gas accounting and verification

ISO 14064-1:2006

Issued by Accredited verification body · Achieved 2023

Conformance to the ISO standard for quantifying and reporting greenhouse gas emissions and removals at the organisation level. Relevant for clients reporting Scope 3 emissions across their supplier base.

  • GHG inventory across operations
  • Reporting aligned to ISO 14064-1 categories
  • Useful evidence for client Scope 3 disclosure

Service Organization Control · Type II

SOC 2

Issued by Independent auditor · Newly attested · 2026

SOC 2 covers the controls a service organisation has in place around security, availability, processing integrity, confidentiality and privacy. Required by most enterprise procurement teams running diligence on a SaaS supplier — and the right complement to ISO 27001 for clients in North American and European markets.

  • Trust Services Criteria audited end-to-end
  • Operating-effectiveness testing across the audit window
  • Annual re-attestation cycle

Security posture

Four pillars, audited annually.

These are the technical control areas that fall within the scope of our ISO 27001 audit. Each one is documented in our Statement of Applicability.

Encryption everywhere

HTTPS / TLS in transit on every client-facing endpoint. JWT-based authentication on the optimisation APIs (per the published Fleet & Network Optimization deck).

Authentication & access

Token refresh, scoped API validation, role-based authorisation per module. Enterprise clients can integrate against their own identity provider on bespoke implementations.

Cloud-based delivery

SaaS on subscription with REST-API integration and a documented ETL platform for data export and transformation. Deployment topology agreed per client engagement.

Auditability

Change-control and audit trails for the operational records that matter most: bookings, rate decisions, stowage plans, fleet schedules. Documented for the ISO 27001 audit cycle.

Where we operate

Five countries. One audit boundary.

Delivery and support span five offices across four regions. Engagement scope, data residency and processing locations are agreed per client and documented in the service definition.

Global offices
5 locations
01
Dubai
UAE
Group HQ
02
Chennai
India
Engineering & Delivery
03
Singapore
Singapore
Ship Management
04
Hamburg
Germany
Europe
05
Yeongwol-gun
South Korea
East Asia
Security disclosures

Found something? Tell us.

If you believe you have identified a security vulnerability in our platform or services, write to enquiry@solverminds.com with the details. Responsible disclosure is welcome and we will work with reporters to validate and remediate legitimate findings.

Email the security team