Switch Achieves ISO/IEC 27001 Certification: Security That Was Always There
.png)
We are proud to announce that Switch is now ISO/IEC 27001:2022 certified — the internationally recognized standard for Information Security Management Systems (ISMS). The certification was granted following an independent third-party audit conducted by the Uruguayan Institute of Technical Standards (UNIT) that validated our processes, controls, and infrastructure against the highest global standard for information security.
"Every time a client works with us, they trust us with something valuable — their data, their systems, their business. That responsibility has never been lost on us, but this certification challenged us to prove it against the most demanding standard in the market. We are proud to have met it”, said Nicolás Zangaro, our CEO and co-founder.
What ISO/IEC 27001 certification actually involves
ISO/IEC 27001 is not a badge you apply for. It's a rigorous framework that requires an organization to systematically identify its information security risks and implement the controls, governance structures, and processes to manage them across the entire business.
Achieving certification means undergoing a formal external audit by an accredited body. The auditors examine how information is classified and handled, how access is managed, how risks are identified and mitigated, how incidents are responded to, and how the organization continuously improves its security posture. Nothing is taken at face value. Everything is tested.
If you want to go deeper into what that means in the context of AI and modern software development, and why it matters more now than ever, we've written a full piece on it: ISO/IEC 27001 Certified: The Security Foundation Every AI Initiative Needs.
The work behind the certification
Getting here wasn't a single event. It was a process, one that required us to examine how we work at every level and ask hard questions about where we could improve.
Over many months, we mapped and documented every process that touches client information. We assessed risks we had managed informally and built formal controls around them. We made changes to our infrastructure, reviewed access management across all systems, formalized our incident response procedures, and established clear policies for how information is classified, handled, retained, and deleted. This required embedding information security culture and risk management at every step. A committee was formed to track these efforts and ensure that all our people were on the same page.
"This certification marks one of our most important milestones, the result of a project that took nearly a year and a half. Developers, testers, project managers, studio leads, managers, everyone had a part in this, and I am deeply grateful for that. This is not the work of one person; building an ISMS requires many roles, many contributions, and an ongoing commitment to keep improving it. This is just the beginning of the journey," said Joaquín Pérez, our CISO.
What comes next
This certification is not a destination; it's a commitment to keep raising the bar. The standard requires ongoing internal audits, periodic external reviews, and a management system that evolves as our work and the threat landscape evolve.
For us, that's not a compliance obligation. It's an extension of something we've always believed: that the organizations that trust us deserve a partner who takes that trust seriously and can prove it.
If you'd like to know more about what this certification means for your specific projects with Switch, or if you're evaluating us as a partner and want to understand our security posture in detail, we're happy to talk.
