Business

Trust & Compliance service overview

blueAPACHE trust and compliance: ISO/IEC 27001:2022 certification scope, security framework alignment, insurance and business stability, and published commercial terms.

This section states blueAPACHE's compliance position precisely, including where certification scope ends. For a regulated buyer, the boundary of a claim is as important as the claim itself, and the pages here are written so that a prospective customer or their auditor can verify what is asserted.

Certification. blueAPACHE holds ISO/IEC 27001:2022, certificate 202507-118, valid 1 August 2025 to 1 August 2028. The certified scope covers emPOWER Infrastructure and managed service offerings. emPOWER Mobile Services sits outside that scope, and portfolio-wide certification claims should be qualified accordingly.

Framework alignment. blueAPACHE aligns to the ASD Essential Eight at Maturity Level 3, to APRA CPS 234, and to the NIST framework. Data centres are certified to Uptime Institute Tier III and Tier IV. Alignment is not certification, and the pages here keep that distinction explicit.

SOC 2. blueAPACHE's posture is described as compliance-aligned. That is not an attestation and should not be read as one.

Insurance and stability. Public liability and professional indemnity cover, contractually committed breach notification, and business continuity management are documented, alongside what blueAPACHE's published general terms actually cover.

Service-level figures, retention periods and recovery objectives are defined in the applicable service catalogue rather than stated here, and no award or data sovereignty claims are made pending verification.