Evidence, not badges.
Break Glass Business does not certify your compliance and does not claim its own certification it has not earned. What it does is produce records — of who could open what, who actually did, and when you last tested any of it — in the shape an assessor asks for.
What we are careful not to claim
Using this product does not make an organisation ISO 27001 certified, SOC 2 compliant, or DORA-ready. Those are assessments of your whole organisation. What the mapping below says is narrower and honest: for these specific controls, the records this product generates are the kind of evidence an assessor will ask you to produce.
Control mapping
Every evidence pack carries this table, and each row names the sections of the pack that speak to that control.
ISO/IEC 27001:2022
| Control | Title | Evidence in the pack |
|---|---|---|
| A.5.15 | Access control | secrets, accessRequests, membership |
| A.5.18 | Access rights (provisioning, review, revocation) | membership, accessReview |
| A.5.26 | Response to information security incidents | incidents, runs |
| A.5.29 | Information security during disruption | playbooks, drills, tabletops |
| A.5.30 | ICT readiness for business continuity | drills, tabletops, recoveryPlans |
| A.8.2 | Privileged access rights | secrets, accessRequests |
SOC 2 (TSC 2017)
| Control | Title | Evidence in the pack |
|---|---|---|
| CC6.1 | Logical access security measures | secrets, accessRequests, membership |
| CC6.2 | Registration and authorisation of new users | membership |
| CC6.3 | Access modification and removal | membership, accessReview |
| CC7.4 | Response to identified security incidents | incidents, runs, messages |
| A1.2 | Recovery and business continuity testing | drills, tabletops, recoveryPlans |
DORA (EU 2022/2554)
| Control | Title | Evidence in the pack |
|---|---|---|
| Art. 11 | Response and recovery | playbooks, recoveryPlans, runs |
| Art. 17 | ICT-related incident management process | incidents, runs |
| Art. 24-26 | Digital operational resilience testing | drills, tabletops |
NIS2 (EU 2022/2555)
| Control | Title | Evidence in the pack |
|---|---|---|
| Art. 21(2)(b) | Incident handling | incidents, messages, runs |
| Art. 21(2)(c) | Business continuity and crisis management | recoveryPlans, drills, tabletops |
| Art. 21(2)(i) | Access control policies and asset management | secrets, accessRequests, membership |
Cyber Essentials
| Control | Title | Evidence in the pack |
|---|---|---|
| Access control | Accounts with special access privileges | secrets, accessRequests, accessReview |
What an evidence pack contains
Included
- Every secret, its quorum, its holders, and when it was last rotated
- Every emergency access request, its stated reason, and each approval or refusal with timestamps
- Membership, role changes and removals across the period
- Playbooks and recovery plans, their versions and publication dates
- Drills and tabletop exercises, with step-by-step outcomes
- Incidents, with time to resolve
- Notification delivery and acknowledgement rates
- Contact verification currency
Deliberately excluded
- Any secret value or ciphertext
- Any key share
- The body of any emergency message
- Contact email addresses and phone numbers
Packs get emailed to auditors and attached to insurance applications. They carry who, when and whether — never what.
Sub-processors
| Provider | Purpose | Data reaching them |
|---|---|---|
| Google Cloud Platform | Hosting, database, encrypted object storage | All stored data, secrets as ciphertext only |
| Resend | Email delivery | Recipient address, subject and body of notifications |
| Twilio | SMS and voice delivery | Recipient number, message text |
| Stripe | Payments | Billing contact and payment details; no operational data |
None of these receive key material or plaintext secrets. Enterprise customers can select EU data residency and supply their own KMS key for envelope encryption of server-side material.
Security questionnaires
Most of what they ask is answered on our security questionnaire page and on Security, written to be quotable directly into a SIG Lite or CAIQ response. Anything left over goes to security@breakglass.business.