Swipe to see all columns →
| Clause | Requirement | Runback capability | Evidence |
|---|---|---|---|
| A.5.15 | Access to information and other associated assets shall be controlled based on business and security requirements. | SSO (OIDC) + team roles (RBAC) | Whether SSO (OIDC) + RBAC is enabled for your org See it in the dashboard → |
| A.8.15 | Logs recording activities, exceptions, faults, and other relevant events shall be produced, kept, and regularly reviewed. | Immutable run ledger + full audit trace | An entry in the hash-chained, append-only ledger See it in the dashboard → |
| A.5.34 | Privacy and protection of personally identifiable information shall be ensured as required by applicable law. | In-process PII redaction before capture | A run where PII was redacted before capture See it in the dashboard → |
| A.5.36 | Compliance with information security policies, rules, and standards shall be regularly reviewed. | Compliance report export (machine-readable) | Aggregated from real run data into a compliance report See it in the dashboard → |
Honest limits
What this page does not claim.
- ISO 27001 covers an organisation's entire information security management system. Runback contributes evidence to a handful of Annex A controls; it is not a substitute for the other ~90.
- Runback itself does not hold ISO 27001 certification today. The security page states exactly what is and isn't certified.
- This is a capability map, not a conformity determination. Whether your deployment satisfies ISO/IEC 27001 is a determination for your own assessor — what's listed above is the evidence that argument draws on.