Quick facts
- Certified company: AENIX s.r.o., Czech Republic
- Standard: ISO/IEC 27001:2022
- Certificate: SIC.MS.008.ISO/IEC27001.5719, issued 27 February 2026, valid through 26 February 2027
- Scope: Software development, IT consulting, hosting, data services, web portals
Customers in banking, insurance and the public sector ask the same question early in every evaluation: how does the vendor itself handle information security? Until now our answer was a set of policies and a lot of explaining. Since February it is also a certificate. AENIX s.r.o. holds ISO/IEC 27001:2022 certification for its information security management system.
What was certified
The certificate, number SIC.MS.008.ISO/IEC27001.5719, was issued on 27 February 2026. Its scope, as written on it, is software development, IT consulting, hosting, data services and web portals — in practice, the work AENIX s.r.o. does for customers, from developing Cozystack and the Ænix platforms to running consulting engagements.
Behind it is the management system the auditors looked at, approved by the CEO on 17 February 2026. It sets out how we assess and treat risk, how information assets are managed and classified, how users are identified and access is granted, how incidents are handled, how documented information is controlled and how the system is audited internally. Each of these has its own policy or procedure, and the system sets measurable objectives with the actions planned to reach them.
The certificate is valid through 26 February 2027 and is renewed through an annual surveillance audit; the next one is scheduled for 27 January 2027, within a three-year cycle that runs to February 2029.
What it means for you, and what it does not
ISO/IEC 27001 certifies a company, not software. It tells you that the people who build, support and host your platform work inside a controlled process: risks are written down and treated, access is not granted by habit, an incident has a procedure and an owner, and someone outside the company checks all of this every year.
It does not turn Cozystack or the Ænix platforms into “certified software”, and it does not certify your environment. If you run a regulated service on Ænix Private Cloud Platform, your scope, your risks and your controls remain yours. What the platform contributes — tenant isolation, audit logging, access control, opt-in volume encryption, declarative change control — is mapped control by control on our compliance evidence pages, for DORA, GDPR, PCI DSS and the CIS Benchmark.
One more distinction matters for procurement. The certificate is held by AENIX s.r.o., the Czech company that contracts with customers in the European Economic Area. AENIX INC, which contracts in the United States, is not named on it.
How to check it
The certificate carries a QR code and its number, which can be checked with the certification body through the System of International Certification. If your vendor assessment needs the signed PDF or copies of our policies, ask us: we send the certificate directly and the policies under NDA. The full details — certification body, accreditation, dates — are on the ISO/IEC 27001 page.



