A&A Audit & Assurance
Not heldNo SOC 2 Type II attestation, no organizational ISO/IEC 27001 certification and no ISO/IEC 42001 certification are held. What does exist is a ten-gate pipeline that runs on every push to main and blocks the deploy on failure: type checking, linting, a secret scan across the working tree and full git history, metadata and claims verification, layout measurement across 44 routes and 24 device classes, a no-JavaScript and reduced-motion degradation suite, a WCAG 2.2 target-size check, and Lighthouse thresholds. That is engineering assurance, not an attestation, and the two are not interchangeable.
Check itThe gate definitions are in .github/workflows/gates.yml and scripts/. The certification position is stated on /security.