Contact us
Request a demo

Memority ISO 27001 and ISO 27701 certified

Memority doubly certified ISO 27001 and ISO 27701 for data security and protection. 20 months of work, 341 pages of documentation: a commitment to quality in the service of your sensitive information.

On the morning of December 25, at 10:33 am, a lovely surprise awaited me under my virtual CISO tree. It wasn't entirely a surprise, nor a gift per se, although it made us all very happy, but rather the result of many months of hard work at Memority. It wasn't Santa Claus who dropped it off, either, but the Certi-Trust certification body.


In the package were two brand-new certifications for Memority:


  • ISO 27001, attesting to our excellence in information security management,
  • and, much rarer, ISO 27701, which also validates our mastery of the personal information management system.

Following its audit in early December, our certification body confirmed and stamped our compliance with both standards. This recognition represents a tremendous reward for all Memority staff, who can be delighted with this result achieved within the timeframe promised, in particular to our customers (before the end of 2024).


Thanks to these certifications, our customers and partners will see their already solid confidence in our ability to protect their data and assets strengthened even further.


A major investment

Obtaining these two certifications represented :


  • just over 20 months of project work by my entire team (in particular Léa Zerah, but also our interns Loïck Chagneau, Adrien Barbier, Paul Ledoux and Arthur Teste), accompanied of course by the entire Memority staff;
  • 341 pages written and published inside and outside the company, comprising 9 safety policies, 11 safety standards, a crisis management manual (one of these documents is even in its 17th version!);
  • 272 pages of documentation, processes and monitoring on our internal wiki;
  • 1,542 permanentcontrol procedures triggered;
  • 2 internal audit missions.

Why is this important?

I think back to a meeting withANSSI representatives a few months ago, when our interlocutors, seasoned experts in offensive security, smiled gently at the mention of ISO 27001, reminding us of what we regularly say: being certified does not mean being secure.


Of course, they're right: ISO 27001 is not intended to guarantee absolute security.


However, this remark reflects a primarily technical vision, focused on threats and vulnerabilities, where the standard plays a more global role. ISO 27001 doesn't just deal with operational aspects. It guarantees that Memority is structured, organized and ready to tackle all aspects of information security with rigor, while committing itself to a dynamic of continuous improvement.


In fact, the auditors went a step further and specified an impressive number of strong points in their report:


  • the involvement of leadership and management (a steering committee that closely follows all security issues and includes the CISO among its members, that's involvement) ;
  • the competence of the teams (they also noted that they were nice, but you can't write that down - it's bound to be subjective);
  • good document management (including accuracy and contextualization within the company: yes, at Memority, it's not ChatGPT that writes the security policies);
  • vulnerability management (I warmly salute our platform security pilots for their involvement in the ongoing handling of this vital subject);
  • the secure development approach (CSSLP certification for our senior devs is not just for show);
  • the control plan (an extremely thankless task);
  • reaction to non-conformities and continuous improvement (when our auditors arrived one morning, action plans to correct the previous day's remarks were already underway - I can understand why this might come as a surprise).

A great project that leads the way

So it's a fine project that's coming to an end, and we can be proud of it.


But it's only the beginning. I said last month in the editorial of "Le petit serrurier", Memority's internal security newsletter, that achieving ISO 27001 certification was a bit like reaching level 60 in an online multiplayer role-playing game: it's not an achievement, but a first step, where everything really begins.


So, if there's no truce in cyberspace, we've earned a little glass of champagne to celebrate our achievement, and then we'll get back to work with the same momentum, in the same state of mind, because that's in Memority's DNA!

Published by

Aymeric Berrendonner

CISO

Aymeric Berrendonner is Chief Information Security Officer (CISO) and Chief Information Officer (CIO) at Memority, where he oversees the company’s overall security as well as the security of the platform delivered to clients. With over 25 years of experience in computer engineering and information security, he leads cybersecurity, risk management, and data protection strategies, while supporting Memority’s technological development. Today, he plays a key role in ensuring the security, compliance, and robustness of Memority’s offerings.

Recent articles

AI agent as a non-human identity accessing enterprise systems
AI agents are becoming new non-human identities to govern

IAM at a turning point: toward more visible, intelligent and dynamic identity management

Calendrier

September 10, 2026

IAM must now govern all identities, including service accounts and AI agents. Discover the three key evolutions (Visible, Intelligent, Dynamic) and why IAM is converging with the SOC to address Zero Trust. Alexis de Calan explains it all in video.

Main robotique et main humaine interagissant avec des icônes d'identité numérique, d'accès et de données, illustrant les agents IA et les identités non humaines

Non-Human Identities and AI Agents: Why IAM Governance Must Expand Its Scope

Calendrier

September 10, 2026

Service accounts, software bots, autonomous AI agents: a new class of identities is spreading across enterprise systems, one that traditional IAM was never built to govern.

Digital identity management in healthcare facilities: How Memority supports HospiConnect compliance

Calendrier

September 8, 2026

See how Memority, an IAM platform, helps healthcare facilities and hospital groups achieve HospiConnect compliance.