generated: '2026-07-19' method: searched source: https://www.helloverify.com/en/technology notes: >- HelloVerify publishes an audited compliance and information-security program on its Technology page and llms.txt. No public API/OpenAPI is exposed, so API-level cross-cutting standards (oauth2, rfc9457, pagination, etc.) are not asserted here — only the published organizational certifications and data-protection posture. standards: - id: iso-27001 name: ISO/IEC 27001:2022 Information Security Management System conforms: true evidence: 'Technology page states ISO 27001:2022 ISMS certification, audited by TUV.' - id: iso-27701 name: ISO/IEC 27701:2019 Privacy Information Management System conforms: true evidence: 'Technology page and llms.txt state ISO 27701 certification (privacy extension to 27001), audited by TUV.' - id: iso-9001 name: ISO 9001:2015 Quality Management System conforms: true evidence: 'Technology page states ISO 9001:2015 QMS certification, audited by TUV.' - id: iso-22301 name: ISO 22301:2019 Business Continuity Management System conforms: true evidence: 'Technology page states ISO 22301:2019 BCMS certification, audited by TUV.' - id: cyber-essentials name: UK Cyber Essentials conforms: true evidence: 'Technology page states Cyber Essentials certification, audited by Predatech.' - id: cyber-essentials-plus name: UK Cyber Essentials Plus conforms: true evidence: 'Technology page states Cyber Essentials Plus certification, audited by Predatech.' - id: gdpr name: EU General Data Protection Regulation conforms: true evidence: 'Technology page and llms.txt describe GDPR-aligned data-protection practices.' - id: pbsa-member name: Professional Background Screening Association membership conforms: true evidence: 'llms.txt and Technology page list PBSA membership.' - id: nsr-member name: National Skills Registry membership conforms: true evidence: 'Technology page lists NSR among professional memberships.'