Skip to main content
The Statement of Applicability (SoA) is a required ISO 27001 document that lists every Annex A control, states whether it applies to our ISMS, records the implementation status, and points to the evidence. This page is the public summary; the full SoA (with sensitive evidence paths) is available under NDA.
Last reviewed: April 2026 · Version: 0.9 (draft, targeted GA Q2 2026) · Owner: Security Officer

Scope of the ISMS

The Denialbase Information Security Management System (ISMS) covers:
  • The Denialbase SaaS platform — production, staging, and development environments.
  • All customer PHI and operational data processed by Denialbase.
  • All Denialbase workforce members (employees, contractors, consultants).
  • All subprocessors that may touch Denialbase customer data (see Subprocessors).
  • Denialbase corporate systems that support the above (GitHub, GCP, Google Workspace, 1Password).

Applicability summary

Totals: 93 applicable, 4 not applicable (N/A), out of 97 Annex A controls in ISO 27001:2022.

Implementation status summary

Exclusions and rationale

Denialbase is a fully remote organization with no physical offices. Workforce security relies on managed workstations, secure home networks, and AUP — devices.
No physical secure areas to protect — see A.7.3 above.
No corporate network with employee web traffic to filter. DNS-level filtering is considered if workforce expands.
All product development is performed by Denialbase employees. No outsourced/offshore development. If this changes, the control will be applicable and tracked.

Review cadence

  • Monthly — control implementation status updated by Security Officer.
  • Quarterly — applicability reviewed with CTO for any scope changes.
  • Annually — full SoA refresh ahead of external audit; mapped to current version of ISO 27001.
  • Ad-hoc — any material architecture or vendor change triggers re-evaluation of affected controls.

How to request the full SoA

The internal SoA includes owner names, ticket links, specific evidence file paths, and private supplier evaluation records. Enterprise customers may request the full document under mutual NDA: security@denialbase.com.