ITEX Trust Centre
Our commitment to ISO-aligned service delivery, information security and responsible technology. Explore how our standards, tools and partners combine to deliver services you can trust.
Our ISO Compliance Framework
We align our operations to six internationally recognised ISO standards, covering quality, security, service management, continuity, risk and AI governance.
ISO 9001
Quality Management
ISO 9001:2015
Defines the criteria for a quality management system. We apply its principles across every service delivery touchpoint to ensure consistent, measurable outcomes for our clients.
At ITEX
Governs how we deliver, measure and continually improve all managed IT services.
ISO 27001
Information Security
ISO/IEC 27001:2022
The international gold standard for information security management systems (ISMS). ITEX is SANcert-certified to this standard — independently audited and verified.
At ITEX
Underpins every security control, data handling practice, and risk treatment across our platform.
ISO 20000
IT Service Management
ISO/IEC 20000-1:2018
Specifies requirements for establishing, implementing, and improving an IT service management system (SMS). Aligns IT services with business and client needs.
At ITEX
Drives our ITSM practices — incident, change, problem and service level management.
ISO 22301
Business Continuity
ISO 22301:2019
International standard for Business Continuity Management Systems (BCMS). Ensures organisations can continue operating during and after disruptive events.
At ITEX
Shapes our backup, disaster recovery and resilience architecture for all clients.
ISO 31000
Risk Management
ISO 31000:2018
Provides guidelines for risk management applicable across any organisation or industry. Defines a universal risk framework for identifying, assessing and treating risks.
At ITEX
Informs our cyber risk assessments, vendor evaluations and security posture reviews.
ISO 42001
AI Management
ISO/IEC 42001:2023
The first international standard for Artificial Intelligence Management Systems (AIMS). Addresses the responsible development and use of AI within organisations.
At ITEX
Guides our adoption of AI-assisted monitoring, automation and intelligent tooling.
ISO/IEC 27001:2022 Certified
ITEX (IT Ex Gratia Pty Ltd) holds an active ISO/IEC 27001:2022 certification issued by SANcert — the South African National Accreditation System-recognised certification body. Our certificate was issued in 2026, confirming that our information security management system has been independently audited and verified against the most demanding global standard for information security.
One System. Six Standards.
Rather than treating each ISO standard in isolation, ITEX operates a fully Integrated Management System (IMS) — a single, unified framework that satisfies the requirements of all six standards simultaneously, reducing duplication and strengthening governance.
Unified policy & procedure library
Policies, controls and procedures are written once and mapped across all applicable ISO clauses — eliminating contradictions and reducing maintenance overhead.
Combined audit & risk cycles
Internal audits, management reviews and risk assessments are planned and executed as a single programme, covering all standards in each cycle.
Continuous improvement across all standards
Nonconformities, corrective actions and improvement opportunities are tracked centrally, feeding back into every standard's performance metrics.
Integrated ISO Management System
ITEX manages its entire IMS through IIMS.app — a purpose-built cloud platform developed by our sister company Gasco, which consolidates all ISO documentation, audit schedules, risk registers, nonconformity tracking and management review workflows into a single, auditable system.
Partners by Service Type
Each partner we deploy is selected for its security posture and alignment with our ISO framework. Below we show which standards apply to each service area and partner.
Managed IT Services
End-to-end IT management covering helpdesk, remote monitoring, patch management and service delivery — all governed by quality and service management frameworks.

Atera
RMM, PSA & Helpdesk Platform
Our primary platform for remote monitoring & management, professional services automation, and client helpdesk. Atera's infrastructure adheres to SOC 2 Type II and aligns with ISO standards for service delivery.
Applicable Standards
Zorin OS
Linux Desktop Operating System
Zorin OS is our managed Linux desktop platform — a secure, low-overhead alternative to Windows for endpoints where licensing, hardware longevity or open-source policy matter. Built on Ubuntu LTS and hardened to align with our ISO 27001 endpoint controls.
Applicable Standards
Apple macOS
macOS Endpoint Management
We deploy, support and manage Apple macOS endpoints across mixed-platform environments — including MDM enrolment, security baselines, FileVault encryption and patching. Apple's hardware and software stack is independently certified to ISO 27001 and other internationally recognised standards.
Applicable Standards
Managed Security Services
Proactive threat detection, endpoint protection and security monitoring — anchored in information security and risk management standards.

ESET
Endpoint Detection & Response
ESET provides enterprise-grade endpoint security across our clients' environments. As an ISO 27001-aligned vendor, ESET's threat intelligence and EDR capabilities strengthen our managed security posture.
Applicable Standards
Microsoft Defender
Cloud-Native Security & SIEM
Microsoft Defender and Sentinel provide cloud-native SIEM/SOAR capabilities integrated into our SOC. Backed by Microsoft's enterprise-grade compliance and ISO certifications.
Applicable Standards

Okta
Identity & Access Management
Okta provides our identity and access management layer — single sign-on, multi-factor authentication and lifecycle management across client environments. Okta is ISO 27001 certified and FedRAMP authorised, directly supporting our access control and identity governance requirements.
Applicable Standards

Wazuh
Open-Source XDR & SIEM
Wazuh is our open-source extended detection and response (XDR) and SIEM platform. It provides real-time log analysis, intrusion detection, vulnerability assessment and compliance reporting — directly supporting our ISO 27001 Annex A monitoring and logging controls.
Applicable Standards
Zorin Grid
Linux Endpoint Security & Policy Management
Zorin Grid is our central security and management plane for Zorin OS fleets — equivalent in role to Microsoft Intune for Windows. We use it to enforce security baselines, control updates, push policies and harden Linux endpoints at scale, directly supporting our ISO 27001 endpoint security controls.
Applicable Standards

Sophos
Next-Gen Firewall & Network Security
Sophos XGS firewalls protect our clients' network perimeters with deep packet inspection, intrusion prevention and SD-WAN. Sophos is ISO 27001 aligned and holds SOC 2 Type II certification.
Applicable Standards
Email Security & Awareness
Protecting the most targeted attack vector — email — and building a human firewall through staff training, phishing simulation and mail-filtering technology.
LibraCyber
Email Security & Mail Filtering (formerly Libraesva)
LibraCyber (rebranded from Libraesva in 2026) provides advanced email filtering, anti-spam, anti-phishing and AI-driven threat protection across our client environments. Its multi-layered scanning engine stops malicious mail before it reaches end-users.
Applicable Standards

Goldphish
Security Awareness & Phishing Simulation
Goldphish is a South African-built security awareness training platform delivering phishing simulations, eLearning and human risk scoring. It directly supports our ISO 27001 Annex A controls for user education.
Applicable Standards
Cloud, Backup & Continuity
Secure cloud infrastructure, data backup and disaster recovery services designed around business continuity and data protection standards.

Redstor
Cloud Backup & Disaster Recovery
Redstor underpins our backup-as-a-service and DR offerings. Their platform is ISO 27001 certified and built around business continuity principles, directly aligning with ISO 22301 requirements.
Applicable Standards
Microsoft Azure
Cloud Infrastructure & IaaS
Azure powers our cloud-hosted workloads and disaster recovery targets. Microsoft Azure is certified to over 100 compliance standards including the full ISO suite referenced here.
Applicable Standards
Responsible AI in Our Back-Office
We use AI internally to make our engineers faster, more consistent and better informed — never at the expense of client confidentiality. All AI usage by ITEX staff is routed through XETI, our internal AI orchestration layer trained on our runbooks, ISO procedures and operational knowledge base. XETI keeps every prompt inside our governance boundary, logs all interactions for audit, and ensures no client data is exposed to public model training. Our use of AI is governed by controls aligned to ISO 27001 and ISO 42001.
Microsoft Copilot
Internal Productivity & Developer Assistance
Microsoft Copilot is used by our team within Microsoft 365 and developer tooling, accessed through XETI's governance layer. Backed by Microsoft's enterprise compliance programme, it inherits Microsoft's full ISO certification stack and EU Data Boundary commitments.
Applicable Standards
ChatGPT (OpenAI)
Internal Reasoning & Drafting
OpenAI's ChatGPT models support our internal drafting, analysis and research workflows via XETI. OpenAI is SOC 2 Type II audited, ISO 27001 and ISO 42001 certified, with enterprise data-handling guarantees that match our governance requirements.
Applicable Standards
Claude (Anthropic)
Long-Context Analysis & Safety-First AI
Anthropic's Claude models are used internally via XETI for long-context document review, code review and high-stakes reasoning where accuracy and safety matter most. Anthropic holds ISO 27001 and ISO 42001 certifications and operates under a published Responsible Scaling Policy.
Applicable Standards
Gemini (Google)
Multimodal Reasoning & Research
Google's Gemini models support our multimodal analysis and research workflows via XETI, complementing our wider Google Workspace footprint. Google Cloud holds ISO 27001, ISO 42001 and ISO 27701 certifications, with enterprise data-handling commitments that meet our governance requirements.
Applicable Standards
Productivity & Collaboration
The productivity suites our clients run on every day — deployed, managed, migrated and security-hardened by ITEX, and backed by internationally recognised quality and security standards.
Microsoft 365
Productivity & Collaboration Suite
Microsoft 365 powers our clients' productivity stack. Microsoft holds numerous ISO certifications and operates under some of the most rigorous compliance programmes in the world.
Applicable Standards
Google Workspace
Productivity, Email & Collaboration
Google Workspace is managed and secured for clients across our portfolio. Google holds ISO 27001, ISO 27017, ISO 27018 and ISO 9001 certifications across its cloud infrastructure.
Applicable Standards
Standard Reference Key
Compliance questions? Let's talk.
Whether you need to meet a regulatory requirement, pass a client audit or simply want to understand your security posture, our team is ready to help.
Get in Touch

