generated: '2026-07-18' method: searched source: https://www.cmtelematics.com/ # CMT publicly states its Information Security Management System is aligned with the # ISO 27001 Standard and SOC 2 Type II Framework, audited annually, and that it holds # an ISO 27701 (PIMS) certificate. These are compliance-program claims, not derived # from an OpenAPI (no public spec is published — the DriveWell SDK/API is gated). standards: - id: iso-27001 conforms: true evidence: CMT states its ISMS is aligned with ISO 27001 and audited against it annually. - id: iso-27701 conforms: true evidence: CMT is among the first U.S. organizations to obtain the ISO 27701 Privacy Information Management System (PIMS) certificate. - id: iso-22301 conforms: true evidence: CMT reports alignment with ISO 22301 (business continuity) in its compliance audits. - id: soc2-type-ii conforms: true evidence: CMT states its ISMS is aligned with the SOC 2 Type II Framework and audited annually. - id: gdpr conforms: true evidence: CMT publishes EEA-specific privacy policies and a data-privacy program (privacy@cmtelematics.com); operates opt-in consent programs. compliance_program: contact: privacy@cmtelematics.com certifications: - ISO 27001 - ISO 27701 - ISO 22301 - SOC 2 Type II privacy_policy: https://www.cmtelematics.com/privacy-policy/