Proton

Proton receives ISO 27001 certification

Proton prioritizes our community’s privacy and data security in every aspect of our business. 

To further demonstrate our commitment, we underwent a rigorous external audit and – on May 2, 2024 – received our ISO 27001(new window) certification.

As an organization founded by scientists who met at CERN, we see peer review and transparency as a cornerstone of our mission. That’s why we make all our apps open source, allowing anyone to examine our code.

Here’s what this latest certification means and what’s next for Proton.

How we did it 

At Proton, our philosophy is to focus first on good security and let compliance with standards and frameworks follow. 

Our philosophy was confirmed by the fact that, to comply with ISO 27001:2022, we only needed to formalize and document some of our current processes. No fundamental changes in how our business or teams operate were required.

This comprehensive audit spanned 14 days and involved over 15 dedicated teams, each thoroughly evaluating the information security management systems underlying all Proton products.  

Basically, our security management operations were double-checked and validated by independent experts.

Why we did it 

At Proton, we believe in building products our community can trust. We also believe that trust must be earned. As an organization founded and run by former scientists, we believe all claims must be not only investigated but verified, including our own

Transparency and peer review are the best ways to ensure systems function as they’re supposed to and vulnerabilities are quickly resolved. This approach only becomes more important as we grow and add new services. This certification not only proves our methodology is sound, it makes it easier for us to work with larger organizations in the future. 

We pursued this certification for the same reason we open our products to scrutiny through external penetration tests and our bug bounty program: To ensure any vulnerabilities in our service are swiftly identified and resolved so your information remains safe. 

What’s next 

Looking ahead, we plan to strengthen support for our business customers, particularly those handling sensitive data, by publishing further information and audit reports detailing our security controls. 

Thank you for being part of our mission to build a better internet where privacy is the default. Stay tuned for more updates and new features designed to keep your data safe and secure.

Proteja su privacidad con Proton
Crear una cuenta gratuita

Compartir esta página

Patricia Egger

Patricia Egger joined Proton in 2021 and is our Security, Risk, and Governance Manager. She received a Master’s degree in Applied Mathematics at the École polytechnique fédérale de Lausanne. Before joining Proton, Patricia worked as a senior security consultant for Deloitte and the security officer for Kudelski Security. She is also the co-founder and Vice President of Women in Cyber Switzerland.

Artículos relacionados

proton scribe
en
Most of us send emails every day. Finding the right words and tone, however, can take up a lot of time. Today we’re introducing Proton Scribe, a smart, privacy-first writing assistant built right into Proton Mail that helps you compose and improve yo
en
People and companies are generally subject to the laws of the country and city where they are located, and those laws can change when they move to a new place. However, the situation becomes more complicated when considering data, which can be subjec
en
Your online data is no longer just used for ads but also for training AI. Google uses publicly available information to train its AI models, raising concerns over whether AI is even compatible with data protection laws. People are worried companies
en
iPhone stores passwords in iCloud Keychain, Apple’s built-in password manager. It’s convenient but has some drawbacks. A major issue is that it doesn’t work well with other platforms, making it hard for Apple users to use their passwords and passkeys
en
There are many reasons you may need to share passwords, bank details, and other highly sensitive information. But we noticed that many people do this via messaging apps or other methods that put your data at risk. In response to the needs of our com
en
  • Novedades de privacidad
Large language models (LLMs) trained on public datasets can serve a wide range of purposes, from composing blog posts to programming. However, their true potential lies in contextualization, achieved by either fine-tuning the model or enriching its p