AENIX s.r.o. holds an ISO/IEC 27001:2022 certificate for its information security management system, issued on 27 February 2026 under number SIC.MS.008.ISO/IEC27001.5719. The scope, as written on the certificate, is software development, IT consulting, hosting, data services and web portals.
The certificate

Certificate № SIC.MS.008.ISO/IEC27001.5719, issued 27 February 2026, valid through 26 February 2027.
| Organisation | AENIX s.r.o., U Trojice 2661/1E, České Budějovice 3, 370 04 České Budějovice, Czech Republic |
| Standard | ISO/IEC 27001:2022, Information security, cybersecurity and privacy protection — Information security management systems — Requirements |
| Scope | Software development, IT consulting, hosting, data services, web portals |
| Issued | 27 February 2026 |
| Valid through | 26 February 2027, renewed on the results of the annual surveillance audit |
| Next surveillance audit | 27 January 2027 |
| Certification cycle | Three years, to 26 February 2029 |
| Certification body | Bureau of International Certification, Kyiv; System of International Certification (SIC) |
| Accreditation of the body | GAS.CB.804.008, Global Accreditation System (GAS), 11 January 2025 |
What the certificate means, and what it does not
ISO/IEC 27001 certifies a management system, not a product. It says that AENIX s.r.o. runs information security as a managed process: risks are assessed and treated, controls from Annex A are selected and justified, incidents are handled by procedure, access is granted and reviewed by procedure, and the whole system is audited internally and by the certification body.
It does not make Cozystack or the Ænix platforms “certified software”, and it does not certify your environment. If you build a regulated service on the platforms, your own scope, risks and controls are yours to manage and, if you need a certificate, yours to certify. What the platforms contribute to that work — tenant isolation, audit logging, access control, encryption, declarative change control — is mapped control by control on the PCI DSS, GDPR, DORA and CIS Benchmark pages.
The certificate is held by AENIX s.r.o., the Czech company. AENIX INC, the US company, is not named on it.
The ISMS behind it
The documented information security management system of AENIX s.r.o. was approved by the CEO, Andrei Kvapil, on 17 February 2026. It includes:
- an information security policy and an instruction on complying with it;
- policies for information asset management, physical security, information security incident management, clean desk and clear screen, and user identification management;
- procedures for information classification, management of documented information, and internal audit;
- measurable ISMS objectives with the actions planned to reach them.
Customers and prospects can receive copies of the policies under NDA, together with the signed certificate.
Verifying the certificate
The certificate carries a QR code and its number, SIC.MS.008.ISO/IEC27001.5719. Both can be checked with the certification body through the System of International Certification at sic-global.com. If your procurement process needs the signed PDF or a confirmation letter, ask us through the contact page.