The Certification

ISO/IEC 27001:2022 certified

ISO/IEC 27001 is the international standard for information security management. Certification means an accredited third party has examined how an organization identifies information risk, what controls it applies, and whether those controls actually operate.

Our system was audited by A-LIGN Compliance and Security, Inc., an ISO/IEC 27001 certification body accredited by the ANSI National Accreditation Board (ANAB) and the United Kingdom Accreditation Service (UKAS). Certification was awarded on August 11, 2026 following a two-stage audit, and it is maintained through annual surveillance audits.

Standard
ISO/IEC 27001:2022
Certificate number
ISMS-AI-081126
Certification body
A-LIGN Compliance and Security, Inc.
Accreditation
ANAB and UKAS
Certified since
August 11, 2026
Valid through
August 11, 2029

A copy of the certificate is available on request. The certificate covers the information security management system that governs how we handle information across our work. Individual products and services are not certified under this standard.

A-LIGN ISO 27001 Certified badge

Certificate ISMS-AI-081126
Issued by A-LIGN

Certified Scope

What the certificate covers

The Information Security Management System (ISMS), in accordance with ISO 27001:2022, supporting the confidentiality, integrity, and availability of client data and Aide Solutions LLC’s internal data related to the design, development, and delivery of AI-powered health economics and outcomes research (HEOR) consulting and technology services. Scope statement, certificate ISMS-AI-081126

The registered activity covers the design, development, and delivery of our AI-powered HEOR software platforms for pharmaceutical and life sciences clients, including automated model generation, research intelligence monitoring, scientific manuscript development, advisory board simulation, and document verification. All in-scope activities are conducted remotely, with no physical location inside the certification boundary.

What Certification Requires

Four things a certificate stands for

Certification is a statement about a system of work rather than a single assessment that has been passed. These are the obligations that come with holding it.

01

A defined scope and a live risk process

Information assets within the certified boundary are inventoried, risks are assessed against them, and treatment decisions are recorded, owned, and revisited.

02

A documented control set

Our statement of applicability covers the control objectives of the ISO/IEC 27001:2022 framework, with an owner and documented evidence behind every applicable control.

03

Independent audit

Certification followed Stage 1 and Stage 2 audits by an accredited certification body. Surveillance audits recur annually, with the first scheduled for July 2027, and recertification follows every three years.

04

Operation through the year

Internal audit, management review, access control, supplier assessment, and incident response run on defined cycles, so the system is exercised continuously rather than assembled for an audit.

For Your Review Teams

Working with security and procurement

Client engagements in life sciences carry a vendor assessment, and we treat that as part of the work rather than an obstacle to it.

  • We complete client security assessments and third party risk questionnaires as part of onboarding.
  • The certificate, its scope statement, and supporting documentation are available on request.
  • Confidentiality agreements are executed before any client material is shared with us.
  • How we handle personal data is set out in our Privacy Policy and U.S. Regional Privacy Notice.

Security questions, documentation requests, and vendor assessments: contact@aidesolutions.net

Reviewing us as a vendor?

Tell us what your security and procurement teams need, and we will send the documentation and complete the assessment.