Compliance officers and procurement teams verifying certifications
Compliance and certifications
Each certification is listed with its auditor and scope, not just its name, so a claim can be checked rather than taken on faith.
Frameworks
ISO/IEC 27001:2022
Information security management system, independently audited.
SOC 2
Controls over security, availability and confidentiality of the service.
HIPAA-aligned
Safeguards designed to meet US health-data handling requirements.
GDPR-aligned
Processing and consent flows designed to meet EU data-protection requirements.
Certification by certification
| Certification | Auditor | Scope | Valid until | Verified by |
|---|---|---|---|---|
| ISO/IEC 27001:2022 | Accredited certification body | Information security management system covering the On-Kare platform. | See certificate on request | security@on-kare.org |
The six questions
- What is it?
- The certifications and legal frameworks On-Kare aligns with, each with the scope it actually covers.
- Who is it for?
- Compliance officers, DPOs and procurement teams running a vendor assessment.
- Which problem does it solve?
- A certification badge without a scope or an expiry date cannot be verified, so it should not be trusted.
- How does it work?
- ISO/IEC 27001:2022 for information security management, SOC 2 for service organisation controls, and design aligned with HIPAA and GDPR for the markets that require them.
- How is it different?
- The certification table below carries an auditor name and a validity date; a listing without both does not appear.
- What is the proof?
- Certificate numbers and audit scope are available on request through the security contact.
This page is part of a platform of 2,156 clinical and operational capabilities across 8 business domains.
Explore the catalogueContinue
Security contact
Coordinated disclosure and documentation requests: security@on-kare.org.
security@on-kare.orgLegal review: 2026-08-24