CertEdge · A SecureEdge Group product

Certified, not just compliant.

CertEdge takes a growing business from the first customer request for ISO 27001 to a certificate, and into the surveillance years after it, in one workspace shared by your team and your auditor. AEGIS checks each piece of evidence against the requirement it answers, and never calls a control ready while mandatory proof is missing.

The certification cycle
1
Scope and gapScope from your own register, gaps with owners.
In CertEdge
2
Build the ISMSStatement of Applicability across all 93 Annex A controls.
Growing
3
EvidenceDated requests, graded by AEGIS, accepted by people.
In CertEdge
4
Internal auditInternal audit and management review.
Coming
5
Certification auditYour auditor in the workspace, an independent decision.
In CertEdge
6
SurveillanceThe next period, with the history intact.
Growing
7
RecertifyA new cycle that starts from the last one.
Growing
The evidence engine

AEGIS: proof before score

Never ready with a gap

AEGIS will not call evidence ready while any mandatory requirement is unsupported. For ISO 27001, mandatory and supporting lines are kept apart.

Words, not a vanity score

Each requirement reads Supported, Partial, Missing or Not checked. There is no percentage to game.

Says what it could not find

Where evidence falls short, AEGIS names what is missing, requirement by requirement.

Every run on the record

Each grading records the model, the prompt version and a checksum of what it read. A page it cannot read is Not checked, never Missing.

AI assists; people accept. AEGIS never accepts evidence on its own.

Separation of duties

Three parties, kept apart

Your acceptance, your auditor's conclusion and the certification decision are recorded separately, by different people, so no one can mark their own work.

Your team

Prepare and accept

Contributors upload and a controller or owner accepts, with a written reason. Nobody accepts their own submission.

Your auditor

Test and conclude

Invited by name, sees only published versions, and concludes separately from your acceptance.

The certification body

Decide

A separate decision-maker, not the auditor, decides on a frozen, hashed dossier, with an independence declaration.

The record

A record an auditor can trust

Tamper-evident log

Every action is written to a hash-chained audit log as it happens, so a later change shows.

Sealed evidence packs

Each framework and cycle closes into a SHA-256 sealed pack that stays verifiable.

Certificates recorded, never issued

The certification body issues your certificate. CertEdge records it and its standing.

Evidence text encrypted

The text extracted from your evidence is encrypted at rest.

Delivered with SecureEdge Advisory

Want a practitioner to run it with you?

SecureEdge Advisory runs ISO 27001 Readiness Sprints inside CertEdge, so the work and the workspace are never out of step.

SecureEdge Advisory →
Request a walkthrough

See CertEdge on your own scope

CertEdge is set up with you, not self-serve. Write to us with what your customers are asking for, and a person will reply to arrange a walkthrough. No card form.