Cookies for anonymous analytics (Microsoft Clarity). Privacy
Legal · Information security
ISMS readiness overview · Last updated 8 July 2026
Download the PDF overviewImportant — please read
This page is a self-assessment prepared by PortLens describing how our practices align to ISO/IEC 27001:2022. PortLens is not ISO/IEC 27001 certified. A certificate can only be issued by an accredited certification body after a formal audit of an Information Security Management System (ISMS); no such certificate has been issued to PortLens. Certification is on our roadmap. Each Annex A theme below is marked In place, Partial or Planned.
ISO 27001 is built around a management system rather than a fixed feature list. PortLens (ABN 59 498 934 467) operates a lightweight ISMS appropriate to a sole-trader business, following Plan-Do-Check-Act: we identify the information assets we hold, assess risks, apply proportionate controls, and review and improve them as the product and threat landscape evolve. Formal ISMS artefacts (policy suite, risk register, Statement of Applicability, internal-audit and management-review records) are in development ahead of a future audit.
The intended scope is the development and operation of the PortLens cloud-based web application, its API and supporting cloud infrastructure, operated by a single owner-operator in Australia. Physical data-centre security is inherited from our cloud sub-processors.
We identify principal information assets — customer account data, user-entered portfolio data, authentication secrets and source code — and the threats to them (data breach, credential theft, cloud outage, ransomware, operator-device loss). Each is treated with proportionate controls. A formally documented, version-controlled risk register is being established.
Complete the documented ISMS (policy suite, risk & asset registers, Statement of Applicability); introduce MFA, rate limiting and access reviews; establish incident-response, business-continuity and disaster-recovery plans with tested evidence; commission penetration testing and continuous scanning; run an internal audit and management review; then engage an accredited certification body for a Stage 1 / Stage 2 ISO/IEC 27001:2022 audit.
For security questionnaires or due-diligence (under mutual NDA), email security@portlens.com.au. See also our Security & SOC 2 overview.