Our information security management system is certified to ISO/IEC 27001:2022, independently audited and issued by A-LIGN. This page sets out what is certified, the scope it covers, and how we work with your security and procurement teams.
ISO/IEC 27001 is the international standard for information security management. Certification means an accredited third party has examined how an organization identifies information risk, what controls it applies, and whether those controls actually operate.
Our system was audited by A-LIGN Compliance and Security, Inc., an ISO/IEC 27001 certification body accredited by the ANSI National Accreditation Board (ANAB) and the United Kingdom Accreditation Service (UKAS). Certification was awarded on August 11, 2026 following a two-stage audit, and it is maintained through annual surveillance audits.
A copy of the certificate is available on request. The certificate covers the information security management system that governs how we handle information across our work. Individual products and services are not certified under this standard.
Certificate ISMS-AI-081126
Issued by A-LIGN
The Information Security Management System (ISMS), in accordance with ISO 27001:2022, supporting the confidentiality, integrity, and availability of client data and Aide Solutions LLC’s internal data related to the design, development, and delivery of AI-powered health economics and outcomes research (HEOR) consulting and technology services. Scope statement, certificate ISMS-AI-081126
The registered activity covers the design, development, and delivery of our AI-powered HEOR software platforms for pharmaceutical and life sciences clients, including automated model generation, research intelligence monitoring, scientific manuscript development, advisory board simulation, and document verification. All in-scope activities are conducted remotely, with no physical location inside the certification boundary.
Certification is a statement about a system of work rather than a single assessment that has been passed. These are the obligations that come with holding it.
Information assets within the certified boundary are inventoried, risks are assessed against them, and treatment decisions are recorded, owned, and revisited.
Our statement of applicability covers the control objectives of the ISO/IEC 27001:2022 framework, with an owner and documented evidence behind every applicable control.
Certification followed Stage 1 and Stage 2 audits by an accredited certification body. Surveillance audits recur annually, with the first scheduled for July 2027, and recertification follows every three years.
Internal audit, management review, access control, supplier assessment, and incident response run on defined cycles, so the system is exercised continuously rather than assembled for an audit.
Client engagements in life sciences carry a vendor assessment, and we treat that as part of the work rather than an obstacle to it.
Security questions, documentation requests, and vendor assessments: contact@aidesolutions.net
Tell us what your security and procurement teams need, and we will send the documentation and complete the assessment.