Loading

Minotore is ISO/IEC 27001:2022 certified.

Minotore builds the digital journeys of financial institutions. Our clients publish their product data through our Asterius platform, across their public websites, their fund finders, their distributor and investor portals, and their regulatory documents.

This data sits at the centre of what we do. We retrieve it, we structure it and we distribute it, on every channel and for every audience. Every piece of published information commits the institution that distributes it: it has to be accurate, current and identical everywhere.

For our clients, securing that data is a regulatory obligation: they have to demonstrate control over their ICT providers. That control runs through how we recruit our teams and grant their access rights, how we develop, how we manage our subcontractors and how we respond to incidents. ISO/IEC 27001:2022 certification provides evidence across all of it.

The certification covers our MDP and Asterius offerings, from design to operation

The certified scope covers the activities, processes, information assets and supporting services involved in designing, building, operating and securing the Minotore Digital Platform (MDP) and Asterius offerings (the multi-tenant version of MDP) for Minotore Group clients.

The management system covers the four control families of ISO/IEC 27001:2022: organisational, people, physical and technological. Our Statement of Applicability sets out the controls we apply and our justified exclusions.

Your vendor reviews now rest on an audited baseline

  • Your security, compliance and procurement teams work from an audited baseline, which shortens onboarding and vendor reviews.
  • Your third-party risk files rest on structured evidence that the certification feeds.
  • Our technical and organisational controls are documented and assessed by an independent third party.
  • Our incident management and notification processes are defined and traceable, which matters when you have your own regulatory reporting deadlines to meet.
  • The system is reassessed every year through an independent surveillance audit, with recertification due by 30 June 2029.

The certification made our practices explicit and traceable

Risk decisions are recorded, security requirements are handled at design time, and our teams follow the same process wherever they are based.

«The way we design, host and operate our clients’ platforms is now assessed by an independent auditor, on a recurring basis.» Houcem Hachicha, Chief Information Security Officer.

You can request the certificate through our Trust Portal

The certificate was issued on 1 July 2026.

Our clients and prospects can request it, along with the full scope wording and our security policies, through the Minotore Trust Portal: https://trust.minotore.com