Thorit is certified to ISO/IEC 27001:2022. The certificate is the short version; the longer one is what the work involved, where AI and automation carried it, where a person had to stay in the loop, and what any of it changes for the companies we work with.
The certificate was issued on 14 September 2026 by Sensiba, and its scope covers the assets, technologies and processes behind CRM and MarTech implementations, website and application development and the consultancy around them, or, in the wording of the certificate itself, the secure provision of HubSpot-centric marketing solutions.
ISO/IEC 27001 is the international standard for an information security management system, which is a less forbidding thing than the name suggests. It is not a list of tools to buy. It is a documented system for deciding what needs protecting, who is accountable for it and how that gets reviewed, together with the evidence that the system is actually running rather than merely written down.
Our Trust Center lists the controls that are in place, and the certificate itself sits on the IAF CertSearch public register, where the status, expiry, entity and scope can be checked without asking us for anything.
Why a certificate rather than an answer sheet
We want to work with enterprises, and enterprises ask before they buy. An offer to a large enterprise prospect came back with a spreadsheet of security questions to verify, and filling in a sheet like that once is a project in its own right; filling it in for every prospect is a department. A certificate answers most of it in a line and a public trust page answers it before anyone has to ask, which is the whole reason for going and getting one.
What it took
29 policies, 86 documents, 138 automated tests, and a stretch of work that did not run at a constant pace. The early part went into learning what the standard actually demands of a company our size and shape, and the focused part was the last six to nine months, once we had brought in an expert who had done it before and put the control framework into Vanta, where each control states the evidence it expects. That turned an interpretation problem into a list.
The surprise was not the process change. We already worked close to the practices the standard asks for, and a restructuring we were doing anyway absorbed much of the rest. What we had underestimated was the writing down: doing a thing well and being able to show that you do it well turn out to be two separate pieces of work, and the second is larger than it looks.
Writing it down is also what found the gaps, none of them dramatic. Which tools are actually in use, who uses them, who reviewed them, who still holds access they were given two projects ago. These are questions nobody can answer from memory and nobody wants to answer by hand twice, which is roughly the definition of something that should have been automated already.
A certificate is also not a finish line. It runs on a three year cycle with surveillance audits in between, so the system has to keep running rather than to have been run once.
Where AI did the work
Policy drafting came first, and it is editing rather than writing. The templates came from Vanta, maintained and written against the standard, and turning one of those into a policy that describes how this company actually works means going through it clause by clause, which we did in passes as the audit came closer rather than all at once. The model produced the draft, and a person decided whether the draft was true.
The same division held for the evidence work around reviews. Take an access review: the raw material is an export of users and permissions, and the work is reading it, which is to say deciding who should still have access to what and what has changed since last time. That decision is a human one and stays a human one. What the model did was turn a long export into something a person can sit down with and actually think about, rather than a table they skim and sign, which is how reviews quietly stop being reviews.
Then there is the document set as a whole. With 29 policies and 86 documents, a decision in one place has consequences in three others, and being able to ask which documents a change touches, and to change only those, is the difference between a living set of documents and a set that gets rewritten once a year and believed by nobody. The same goes for the control framework itself: which test proves which control, which evidence satisfies which test, and what is still open.
Underneath all of it is one pattern. The knowledge was already in the company; what was missing was the register, the formal and auditable way of saying it. Talking a process through informally and getting back a document in the right form meant the people who actually run a process could document it themselves, without first having to learn to write like an auditor.
Where automation did the work
Automation ran in the same place rather than in scripts of our own, and once we had consolidated onto AWS and GitLab the platform could read them directly, so a large share of the tests ran themselves.
The gain there is not the saved hours. A manual export is true on the day it is taken and drifts every day afterwards, so by the time of an audit you are showing evidence about a state that has already moved, while an automated test is true now.
Where a person was not optional
The AI was good at producing things that read correct, and not reliable at knowing which of them were correct for us. The expert we brought in spent most of the time on two sentences: this clause is not relevant for a company of your shape, cut it or reshape it into something you will actually use, and this one is in scope and you have not gone deep enough. Neither judgement is in the text of the standard, and both are available from someone who has sat through a few audits.
Left alone, a model also builds more than the first step needs. Asked for a process, it will design the complete and mature version of that process, with roles and review cycles a company of our size does not have, so somebody has to say that step one is smaller than that and then set the structure the model works inside. It overshot in places and missed small details in others, company scope among them, all of which a second read caught long before anything reached an auditor.
What changed in how we work
Less in the day job than you would expect, and more underneath it. The access questions got automated, partly because answering them by hand at the frequency the standard expects is not sustainable, and partly because the automation produces the documentation as a by-product rather than as a second task. We now review what a tool does with data before it comes in, and that review doubles as a list colleagues can check, which in a company that tries a lot of tools is useful in both directions. For the engineers the change is a habit rather than a rule: a second thought about where data goes, which systems it passes through and where it comes to rest.
The same principles now shape what we build for clients. Separation of data and least privilege access, so that “who can reach this” has an answer shorter than a meeting. An incident response path that names an owner and can be acted on quickly, including on platforms used by only a few projects, which is usually where responsibility goes vague. Evidence that runs continuously instead of being reconstructed for a review.
What it means if you work with us
Most security questionnaires are now answered by the certificate and the Trust Center, which moves the trust conversation to before the project rather than into the middle of it, and specific requirements have specific answers: European hosting when data may not leave the EU, masked data when a test environment needs something realistic and must not have the real thing. There is also a named person internally to ask when an ISO question comes up in a project, instead of a search for whoever might know.
The part that matters more is scope. HubSpot carries a great deal of this inside HubSpot, with EU hosting and its own certifications, but the work is increasingly what sits around it: portals and custom software on top of the CRM, integrations to systems that were never designed to speak to each other, agents acting inside those flows. Data moves through what we build. A platform’s certificate covers the platform, and the work around it is ours to manage, which it now is, inside a system somebody audits.
What does not change is everything client facing. We are not in the certification business and this is not a new service line. We consult the same way, on the same things, with the same opinions. The difference is that the answer to what happens to your data in a project with us is now written down, reviewed and testable, rather than assembled on request.



