Evidence, not badges.

Break Glass Business does not certify your compliance and does not claim its own certification it has not earned. What it does is produce records — of who could open what, who actually did, and when you last tested any of it — in the shape an assessor asks for.

What we are careful not to claim

Using this product does not make an organisation ISO 27001 certified, SOC 2 compliant, or DORA-ready. Those are assessments of your whole organisation. What the mapping below says is narrower and honest: for these specific controls, the records this product generates are the kind of evidence an assessor will ask you to produce.

Control mapping

Every evidence pack carries this table, and each row names the sections of the pack that speak to that control.

ISO/IEC 27001:2022

ControlTitleEvidence in the pack
A.5.15Access controlsecrets, accessRequests, membership
A.5.18Access rights (provisioning, review, revocation)membership, accessReview
A.5.26Response to information security incidentsincidents, runs
A.5.29Information security during disruptionplaybooks, drills, tabletops
A.5.30ICT readiness for business continuitydrills, tabletops, recoveryPlans
A.8.2Privileged access rightssecrets, accessRequests

SOC 2 (TSC 2017)

ControlTitleEvidence in the pack
CC6.1Logical access security measuressecrets, accessRequests, membership
CC6.2Registration and authorisation of new usersmembership
CC6.3Access modification and removalmembership, accessReview
CC7.4Response to identified security incidentsincidents, runs, messages
A1.2Recovery and business continuity testingdrills, tabletops, recoveryPlans

DORA (EU 2022/2554)

ControlTitleEvidence in the pack
Art. 11Response and recoveryplaybooks, recoveryPlans, runs
Art. 17ICT-related incident management processincidents, runs
Art. 24-26Digital operational resilience testingdrills, tabletops

NIS2 (EU 2022/2555)

ControlTitleEvidence in the pack
Art. 21(2)(b)Incident handlingincidents, messages, runs
Art. 21(2)(c)Business continuity and crisis managementrecoveryPlans, drills, tabletops
Art. 21(2)(i)Access control policies and asset managementsecrets, accessRequests, membership

Cyber Essentials

ControlTitleEvidence in the pack
Access controlAccounts with special access privilegessecrets, accessRequests, accessReview

What an evidence pack contains

Included

  • Every secret, its quorum, its holders, and when it was last rotated
  • Every emergency access request, its stated reason, and each approval or refusal with timestamps
  • Membership, role changes and removals across the period
  • Playbooks and recovery plans, their versions and publication dates
  • Drills and tabletop exercises, with step-by-step outcomes
  • Incidents, with time to resolve
  • Notification delivery and acknowledgement rates
  • Contact verification currency

Deliberately excluded

  • Any secret value or ciphertext
  • Any key share
  • The body of any emergency message
  • Contact email addresses and phone numbers

Packs get emailed to auditors and attached to insurance applications. They carry who, when and whether — never what.

Sub-processors

ProviderPurposeData reaching them
Google Cloud PlatformHosting, database, encrypted object storageAll stored data, secrets as ciphertext only
ResendEmail deliveryRecipient address, subject and body of notifications
TwilioSMS and voice deliveryRecipient number, message text
StripePaymentsBilling contact and payment details; no operational data

None of these receive key material or plaintext secrets. Enterprise customers can select EU data residency and supply their own KMS key for envelope encryption of server-side material.

Security questionnaires

Most of what they ask is answered on our security questionnaire page and on Security, written to be quotable directly into a SIG Lite or CAIQ response. Anything left over goes to security@breakglass.business.