generated: '2026-09-06' method: searched source: https://solutions.autopay.io/about-us/iso-certifications description: >- Autopay Technologies AS publishes a certifications page on its corporate site rather than a dedicated trust portal. There is no document request flow, no sub-processor list and no downloadable audit report — the page names three ISO certifications and answers a short set of security and privacy FAQs. trust_center: published: true url: https://solutions.autopay.io/about-us/iso-certifications http_status: 200 checked: '2026-09-06' form: static marketing page (Squarespace), not a gated trust portal document_request: none offered subprocessors_published: false pen_test_summary_published: false uptime_published: false certifications: - id: iso-27001 name: ISO/IEC 27001 scope_claimed: Information security management for the Autopay parking platform certificate_number: not published certification_body: not published valid_until: not published quote: >- "Our ISO 27001 certification demonstrates our commitment to information security through rigorous risk management, robust data protection practices and continual security enhancements." - id: iso-9001 name: ISO 9001 scope_claimed: Quality management certificate_number: not published policy_page: https://solutions.autopay.io/about-us/iso-certifications/quality-policy - id: iso-14001 name: ISO 14001 scope_claimed: Environmental management certificate_number: not published policy_page: https://solutions.autopay.io/about-us/iso-certifications/environmental-policy - id: hse name: HSE policy type: published policy (not a certification) policy_page: https://solutions.autopay.io/about-us/iso-certifications/hse-policy compliance: - id: gdpr name: EU General Data Protection Regulation claimed: true quote: >- "Autopay is committed to processing personal data in accordance with the General Data Protection Regulation (GDPR) and applicable privacy legislation." privacy_notice: https://solutions.autopay.io/privacy-policy not_claimed: - SOC 2 - PCI DSS - ISO 27017 / 27018 - HIPAA - FedRAMP - TISAX security_contacts: vulnerability_reports: security@autopay.io security_txt: https://autopay.io/.well-known/security.txt see_also: security/autopay-vulnerability-disclosure.yml gaps: - No certificate numbers, certification bodies, audit dates or scope statements are published, so the certifications cannot be independently verified from the page. - No bug bounty or coordinated-disclosure policy is published; security.txt carries a Contact but no Policy line.