For partners and buyers

ISO 27001

In one sentence

ISO 27001 is the international standard for an information security management system, and it is the certificate a security review asks a software supplier for.

ISO 27001 is the international standard for an information security management system, which covers how an organisation manages risk, access, suppliers and security incidents. It describes how security is managed and it does not certify that any single product feature is safe.

In diagnostics your supplier is usually a laboratory partner and a software vendor at the same time, which means your security review and your data protection review ask for different documents. Aniva processes data EU-native on infrastructure hosted in Germany, and an AVV, the German data processing agreement, is included.

A certificate with a narrow scope can exclude the exact system that will hold your customer data, so the scope statement is worth more to you than the certificate number.

  • Ask for the certificate together with the statement of applicability behind it.
  • Ask which legal entity and which systems are inside the certified scope.
  • Ask where personal data is processed and which subprocessors are involved.
  • Ask how API keys are issued, rotated and revoked for your own integration.

In this glossary, DSGVO explains the data protection side of the same review, LIMS covers the system that holds laboratory data, and REST API covers the interface your engineers will use.

This glossary entry is general information, not medical advice, and it is not intended to diagnose, treat or rule out any condition. Discuss your own results with a clinician who knows your history.

Your future self is waiting

Start building the healthiest decade of your life.

Get Started