Last updated 26 August 2026
Security & Compliance
Most vendor security questionnaires ask the same forty questions. This page answers them in advance, and says plainly where the honest answer is "not applicable" rather than dressing it up.
Frameworks we work in
| Framework | What we do with it |
|---|---|
| ISO/IEC 27001:2022 | Gap analysis through to certification audit. Karol is a Lead Implementer certified by BSI. |
| SOC 2 · ISAE 3402 | Readiness for Type I and Type II: scoping the trust services criteria, closing gaps, and standing beside you through the auditor's fieldwork. |
| GDPR | Records of processing, technical and organisational measures, DPIAs, breach procedures. Outsourced Data Protection Officer. |
| Swiss FADP (revised) | Data Protection Advisor, held simultaneously with the GDPR role — useful where entities straddle the EU and Switzerland. |
| Cyber Essentials · Cyber Essentials Plus · IASME Cyber Assurance | Implemented end to end for a UK entity, including the assessed Plus tier. |
How this website is built
A consultancy that advises on security should be able to describe its own attack surface. Ours is deliberately close to zero:
- Static files only. No content management system, no administrative panel, no database, no server-side code. There is no application layer to attack.
- No third-party requests. Fonts, images and video are served from this domain. No CDN, no analytics, no tag manager, no embedded widgets.
- No cookies and no client-side storage. Nothing is written to your browser, so there is nothing to consent to and nothing to leak.
- No forms. Nothing is submitted anywhere; the contact address is an ordinary mail link.
- Version-controlled and public. Every change to this site is a commit in a public repository, so its history is auditable by anyone.
This is a deliberate change of posture. The previous site ran on WordPress and was compromised in July 2026. The installation was current on the day of the attack, with a stock theme and three plugins — keeping the software up to date, the defence users are told to rely on, did not prevent it. The response was not to harden the same architecture but to remove it. The underlying issue has been reported to the platform's security team; we will describe it here once they have assessed it and any fix is available.
Our own operations
- Multi-factor authentication on every account that supports it.
- Unique, randomly generated credentials per service, held in a password manager.
- Client material kept only for as long as the engagement and the law require, then deleted. We prefer to work in your systems rather than hold copies in ours.
- Email on EU-hosted infrastructure with SPF and DMARC published.
- Devices running current, supported operating systems with full-disk encryption.
Where the honest answer is "no"
We are a small firm and will not pretend otherwise. WarsawIQ does not hold its own ISO/IEC 27001 certificate, does not operate a 24/7 security operations centre, and does not carry a formal, independently audited control set of its own. What we bring is people who have built and been audited on those things inside larger regulated businesses. If your procurement process requires a certified supplier rather than a certified practitioner, say so early and we will tell you straight away whether we can meet it.
Reporting a security problem
If you find a vulnerability in this site or in anything we have built for you, write to karol.chlasta@warsawiq.com. We will acknowledge within two working days, keep you informed while we fix it, and credit you if you would like to be named. We will not threaten anyone who reports a problem in good faith.