Internal alignment page
ISO 27001 alignment
SkyRental is built with ISO/IEC 27001 in mind. This checklist tracks which controls we currently meet. This page is not linked from public navigation.
12/20
controls met
- Information security policy documented and communicated
- Defined roles and responsibilities for security
- Access control (least privilege, RBAC via user_roles)
- Row-Level Security enforced on all sensitive tables
- Encryption in transit (TLS) for all traffic
- Encryption at rest for database and object storage
- Password protection against leaked credentials
- Secure software development lifecycle (code review, scans)
- Dependency vulnerability scanning and patching
- Logging and monitoring of security-relevant events
- Incident response plan and communication channels
- Regular data backups and tested restore procedures
- Business continuity and disaster recovery plan
- Supplier / third-party risk assessments
- Employee security awareness training
- Physical security of hosting infrastructure (cloud)
- Cryptographic key management
- Data classification and handling procedures
- Privacy by design and GDPR-style data subject rights
- Internal audits and management review
