ITEX Trust Centre | Security & Compliance
Compliance & Trust

ITEX Trust Centre

Our commitment to ISO-aligned service delivery, information security and responsible technology. Explore how our standards, tools and partners combine to deliver services you can trust.

Our ISO Compliance Framework

We align our operations to six internationally recognised ISO standards, covering quality, security, service management, continuity, risk and AI governance.

ISO 9001

Quality Management

Compliant

ISO 9001:2015

Defines the criteria for a quality management system. We apply its principles across every service delivery touchpoint to ensure consistent, measurable outcomes for our clients.

At ITEX

Governs how we deliver, measure and continually improve all managed IT services.

ISO 27001

Information Security

Certified

ISO/IEC 27001:2022

The international gold standard for information security management systems (ISMS). ITEX is SANcert-certified to this standard — independently audited and verified.

At ITEX

Underpins every security control, data handling practice, and risk treatment across our platform.

ISO 20000

IT Service Management

Compliant

ISO/IEC 20000-1:2018

Specifies requirements for establishing, implementing, and improving an IT service management system (SMS). Aligns IT services with business and client needs.

At ITEX

Drives our ITSM practices — incident, change, problem and service level management.

ISO 22301

Business Continuity

Compliant

ISO 22301:2019

International standard for Business Continuity Management Systems (BCMS). Ensures organisations can continue operating during and after disruptive events.

At ITEX

Shapes our backup, disaster recovery and resilience architecture for all clients.

ISO 31000

Risk Management

Compliant

ISO 31000:2018

Provides guidelines for risk management applicable across any organisation or industry. Defines a universal risk framework for identifying, assessing and treating risks.

At ITEX

Informs our cyber risk assessments, vendor evaluations and security posture reviews.

ISO 42001

AI Management

Compliant

ISO/IEC 42001:2023

The first international standard for Artificial Intelligence Management Systems (AIMS). Addresses the responsible development and use of AI within organisations.

At ITEX

Guides our adoption of AI-assisted monitoring, automation and intelligent tooling.

ISO/IEC 27001:2022 Certified
Certified bySANcert
View Certificate
Active Certification

ISO/IEC 27001:2022 Certified

ITEX (IT Ex Gratia Pty Ltd) holds an active ISO/IEC 27001:2022 certification issued by SANcert — the South African National Accreditation System-recognised certification body. Our certificate was issued in 2026, confirming that our information security management system has been independently audited and verified against the most demanding global standard for information security.

Independently audited
SANcert issued
Certificate issued 2026
Integrated Management System

One System. Six Standards.

Rather than treating each ISO standard in isolation, ITEX operates a fully Integrated Management System (IMS) — a single, unified framework that satisfies the requirements of all six standards simultaneously, reducing duplication and strengthening governance.

Unified policy & procedure library

Policies, controls and procedures are written once and mapped across all applicable ISO clauses — eliminating contradictions and reducing maintenance overhead.

Combined audit & risk cycles

Internal audits, management reviews and risk assessments are planned and executed as a single programme, covering all standards in each cycle.

Continuous improvement across all standards

Nonconformities, corrective actions and improvement opportunities are tracked centrally, feeding back into every standard's performance metrics.

IMS Platform
IIMS.app

Integrated ISO Management System

ITEX manages its entire IMS through IIMS.app — a purpose-built cloud platform developed by our sister company Gasco, which consolidates all ISO documentation, audit schedules, risk registers, nonconformity tracking and management review workflows into a single, auditable system.

ISO 9001 module
ISO 27001 module
ISO 20000 module
ISO 22301 module
ISO 31000 module
ISO 42001 module
Visit iims.app

Partners by Service Type

Each partner we deploy is selected for its security posture and alignment with our ISO framework. Below we show which standards apply to each service area and partner.

Managed IT Services

End-to-end IT management covering helpdesk, remote monitoring, patch management and service delivery — all governed by quality and service management frameworks.

Learn more
Atera logo

Atera

RMM, PSA & Helpdesk Platform

Our primary platform for remote monitoring & management, professional services automation, and client helpdesk. Atera's infrastructure adheres to SOC 2 Type II and aligns with ISO standards for service delivery.

Applicable Standards

ISO 9001ISO 20000ISO 27001
Zorin OS logo

Zorin OS

Linux Desktop Operating System

Zorin OS is our managed Linux desktop platform — a secure, low-overhead alternative to Windows for endpoints where licensing, hardware longevity or open-source policy matter. Built on Ubuntu LTS and hardened to align with our ISO 27001 endpoint controls.

Applicable Standards

ISO 27001ISO 20000
Apple macOS logo

Apple macOS

macOS Endpoint Management

We deploy, support and manage Apple macOS endpoints across mixed-platform environments — including MDM enrolment, security baselines, FileVault encryption and patching. Apple's hardware and software stack is independently certified to ISO 27001 and other internationally recognised standards.

Applicable Standards

ISO 27001ISO 20000

Managed Security Services

Proactive threat detection, endpoint protection and security monitoring — anchored in information security and risk management standards.

Learn more
ESET logo

ESET

Endpoint Detection & Response

ESET provides enterprise-grade endpoint security across our clients' environments. As an ISO 27001-aligned vendor, ESET's threat intelligence and EDR capabilities strengthen our managed security posture.

Applicable Standards

ISO 27001ISO 31000
Microsoft Defender logo

Microsoft Defender

Cloud-Native Security & SIEM

Microsoft Defender and Sentinel provide cloud-native SIEM/SOAR capabilities integrated into our SOC. Backed by Microsoft's enterprise-grade compliance and ISO certifications.

Applicable Standards

ISO 27001ISO 31000
Okta logo

Okta

Identity & Access Management

Okta provides our identity and access management layer — single sign-on, multi-factor authentication and lifecycle management across client environments. Okta is ISO 27001 certified and FedRAMP authorised, directly supporting our access control and identity governance requirements.

Applicable Standards

ISO 27001ISO 31000
Wazuh logo

Wazuh

Open-Source XDR & SIEM

Wazuh is our open-source extended detection and response (XDR) and SIEM platform. It provides real-time log analysis, intrusion detection, vulnerability assessment and compliance reporting — directly supporting our ISO 27001 Annex A monitoring and logging controls.

Applicable Standards

ISO 27001ISO 31000
Zorin Grid logo

Zorin Grid

Linux Endpoint Security & Policy Management

Zorin Grid is our central security and management plane for Zorin OS fleets — equivalent in role to Microsoft Intune for Windows. We use it to enforce security baselines, control updates, push policies and harden Linux endpoints at scale, directly supporting our ISO 27001 endpoint security controls.

Applicable Standards

ISO 27001ISO 31000
Sophos logo

Sophos

Next-Gen Firewall & Network Security

Sophos XGS firewalls protect our clients' network perimeters with deep packet inspection, intrusion prevention and SD-WAN. Sophos is ISO 27001 aligned and holds SOC 2 Type II certification.

Applicable Standards

ISO 27001ISO 31000

Email Security & Awareness

Protecting the most targeted attack vector — email — and building a human firewall through staff training, phishing simulation and mail-filtering technology.

Learn more
LibraCyber logo

LibraCyber

Email Security & Mail Filtering (formerly Libraesva)

LibraCyber (rebranded from Libraesva in 2026) provides advanced email filtering, anti-spam, anti-phishing and AI-driven threat protection across our client environments. Its multi-layered scanning engine stops malicious mail before it reaches end-users.

Applicable Standards

ISO 27001ISO 31000
Goldphish logo

Goldphish

Security Awareness & Phishing Simulation

Goldphish is a South African-built security awareness training platform delivering phishing simulations, eLearning and human risk scoring. It directly supports our ISO 27001 Annex A controls for user education.

Applicable Standards

ISO 27001ISO 42001

Cloud, Backup & Continuity

Secure cloud infrastructure, data backup and disaster recovery services designed around business continuity and data protection standards.

Learn more
Redstor logo

Redstor

Cloud Backup & Disaster Recovery

Redstor underpins our backup-as-a-service and DR offerings. Their platform is ISO 27001 certified and built around business continuity principles, directly aligning with ISO 22301 requirements.

Applicable Standards

ISO 27001ISO 22301ISO 31000
Microsoft Azure logo

Microsoft Azure

Cloud Infrastructure & IaaS

Azure powers our cloud-hosted workloads and disaster recovery targets. Microsoft Azure is certified to over 100 compliance standards including the full ISO suite referenced here.

Applicable Standards

ISO 9001ISO 20000ISO 27001ISO 22301

Responsible AI in Our Back-Office

We use AI internally to make our engineers faster, more consistent and better informed — never at the expense of client confidentiality. All AI usage by ITEX staff is routed through XETI, our internal AI orchestration layer trained on our runbooks, ISO procedures and operational knowledge base. XETI keeps every prompt inside our governance boundary, logs all interactions for audit, and ensures no client data is exposed to public model training. Our use of AI is governed by controls aligned to ISO 27001 and ISO 42001.

Microsoft Copilot logo

Microsoft Copilot

Internal Productivity & Developer Assistance

Microsoft Copilot is used by our team within Microsoft 365 and developer tooling, accessed through XETI's governance layer. Backed by Microsoft's enterprise compliance programme, it inherits Microsoft's full ISO certification stack and EU Data Boundary commitments.

Applicable Standards

ISO 27001ISO 42001ISO 9001
ChatGPT (OpenAI) logo

ChatGPT (OpenAI)

Internal Reasoning & Drafting

OpenAI's ChatGPT models support our internal drafting, analysis and research workflows via XETI. OpenAI is SOC 2 Type II audited, ISO 27001 and ISO 42001 certified, with enterprise data-handling guarantees that match our governance requirements.

Applicable Standards

ISO 27001ISO 42001
Claude (Anthropic) logo

Claude (Anthropic)

Long-Context Analysis & Safety-First AI

Anthropic's Claude models are used internally via XETI for long-context document review, code review and high-stakes reasoning where accuracy and safety matter most. Anthropic holds ISO 27001 and ISO 42001 certifications and operates under a published Responsible Scaling Policy.

Applicable Standards

ISO 27001ISO 42001
Gemini (Google) logo

Gemini (Google)

Multimodal Reasoning & Research

Google's Gemini models support our multimodal analysis and research workflows via XETI, complementing our wider Google Workspace footprint. Google Cloud holds ISO 27001, ISO 42001 and ISO 27701 certifications, with enterprise data-handling commitments that meet our governance requirements.

Applicable Standards

ISO 27001ISO 42001ISO 27701

Productivity & Collaboration

The productivity suites our clients run on every day — deployed, managed, migrated and security-hardened by ITEX, and backed by internationally recognised quality and security standards.

Learn more
Microsoft 365 logo

Microsoft 365

Productivity & Collaboration Suite

Microsoft 365 powers our clients' productivity stack. Microsoft holds numerous ISO certifications and operates under some of the most rigorous compliance programmes in the world.

Applicable Standards

ISO 9001ISO 20000ISO 27001
Google Workspace logo

Google Workspace

Productivity, Email & Collaboration

Google Workspace is managed and secured for clients across our portfolio. Google holds ISO 27001, ISO 27017, ISO 27018 and ISO 9001 certifications across its cloud infrastructure.

Applicable Standards

ISO 9001ISO 27001

Standard Reference Key

ISO 9001 — Quality ManagementISO 27001 — Information SecurityISO 20000 — IT Service ManagementISO 22301 — Business ContinuityISO 31000 — Risk ManagementISO 42001 — AI Management

Compliance questions? Let's talk.

Whether you need to meet a regulatory requirement, pass a client audit or simply want to understand your security posture, our team is ready to help.

Get in Touch