News & Updates

ISO 27001 for your optimization vendor: what it changes in a security review

Solvice is now certified to ISO 27001. For the platforms that embed our solver, the useful part is not the certificate. It is that your customer's security questionnaire now has an independent assessment behind it, and a trust center your team can answer most of it from without waiting on us.

By
Bert Van Wassenhove
on
16/09/2026
"The integration took a week. The security review took two months."

Anyone who has embedded a third-party API into a platform that enterprises buy knows that shape. The engineering work is bounded and you can estimate it. Then your customer's security team sends the questionnaire, and one row asks who else touches the data. Your routing vendor is now on that list, and a product manager who wanted to ship a dispatch feature is instead chasing a supplier for a penetration test summary and a subprocessor list.

Solvice is now certified to ISO 27001. This post is about what that changes for the platforms that run on us, and what it does not.

The questionnaire stops with you, not with us

When you embed optimization, you inherit its security posture. Your customer has no contract with your solver vendor. They have one with you. So the assessment lands on your desk, and every unanswered row about a subprocessor is a row you have to go and ask someone else about.

That round trip is the actual cost. Not the control itself, which is usually fine, but the two weeks it takes to get a document out of a vendor who was not expecting to be asked. Field service platforms, last-mile delivery platforms and workforce schedulers all hit this at the same point in the sales cycle: after the technical evaluation is won, when procurement starts.

What ISO 27001 actually certifies

It is not a product feature and it is not a penetration test. ISO 27001 certifies an information security management system: the set of controls an organization runs, and the evidence that it runs them consistently rather than when someone remembers to.

In our case the auditor examined access management, secure development, penetration testing, vulnerability scanning and change management. An accredited body went through them and assessed them independently. That independence is the whole point. A vendor saying it takes security seriously is not evidence. An external assessment of a documented system is.

Nothing in the API changed

No new endpoints, no migration, no version bump, no change to how you authenticate or how you POST a problem. The controls the auditor looked at were already how we work. Certification did not introduce them, it verified them.

This is worth stating clearly. Certification is not the moment a vendor becomes secure. It is the moment the way it already worked becomes something a third party will vouch for, which is the part your customer's security team can actually use.

What your team can do with it now

Our trust center sets out the certifications, the controls behind them and our subprocessors. At the time of writing that is 9 access management controls and 7 product security controls, plus penetration testing, vulnerability scanning and change management, with Auth0 for identity and access and GCP for cloud listed as subprocessors.

The practical consequence: most of a vendor questionnaire can be answered by your team, from a page, at the moment the questionnaire arrives. No ticket to us, no wait, no chasing a PDF. When something is genuinely not published there, ask us and we will send it.

Where to look

The certifications, controls and subprocessor list are at trust.www.solvice.io. If you have an assessment running and need something that is not published there, contact us and we will send it.

News & Updates

Route optimization ROI: where the money actually shows up

News & Updates

Low-code and AI optimization: superpowers without the black box

News & Updates

2025 in Review - Route Optimization at Scale: Key API Features for Field Service and Last Mile Delivery