Decoresmart
Decoresmart Earns ISO/IEC 27001 Certification for Its Connected-Home Platform
Company News

Decoresmart Earns ISO/IEC 27001 Certification for Its Connected-Home Platform

Decoresmart Earns ISO/IEC 27001 Certification for Its Connected-Home Platform

A smart lock protects a door, but the system behind it protects something subtler: the daily rhythm of a household, recorded as access events, notification preferences, and in the case of face recognition models, biometric templates. Decoresmart takes that responsibility seriously, which is why we spent the past year rebuilding our information security management around a single international benchmark. We are now proud to announce that DEC’s connected-home platform, including the DEC cloud service and the DEC companion app, operates under an ISO/IEC 27001 certified information security management system.

Why ISO 27001, and Why Now

Smart home buyers have learned to ask harder questions. A lock that talks to an app, a cloud, and a voice assistant is a small data ecosystem, and regulators across our markets, from Europe’s GDPR to similar frameworks elsewhere, expect vendors to manage that ecosystem deliberately. Certification does not replace good engineering, but it forces an organization to write down how it protects data, prove the controls work, and keep improving them under audit. That discipline is what we wanted, not just the certificate.

The timing also reflects our B2B growth. Hotels, property managers, and OEM partners increasingly run vendor security reviews before signing, and they deserve answers that stand up to their own compliance teams.

What the Audit Covered

The certified management system spans the full life cycle of our connected products, not just a server room:

  • Cloud infrastructure that stores account data, device metadata, and access event history.
  • Data flows between locks, the DEC app, gateways, and third-party integrations.
  • Manufacturing and office IT systems, including access control and supplier communications.
  • Incident response and business continuity procedures, tested through tabletop exercises.
  • Staff security training and a formal risk register reviewed by management each quarter.

The external audit included document review, on-site assessment, and sampling of real processes, and the certificate will be maintained through annual surveillance audits.

What It Means for the People at the Door

For households, the practical commitments are easy to state. Face templates on our 3D recognition locks are processed and stored on the lock itself, not uploaded to a cloud album. Communication between lock and app is encrypted in transit. Access history belongs to the account holder and can be exported or deleted from the app at any time. And when a lock is reset for a new owner, its local data goes with it.

None of these behaviors are new; several have shipped since our earliest connected models. What certification adds is evidence that they are documented, audited, and maintained as the product line evolves.

For Our B2B and OEM/ODM Partners

Enterprise customers get concrete artifacts they can hand to their own compliance departments:

  • Signed data processing agreements aligned with GDPR requirements for EU deployments.
  • Penetration test summaries available to qualified partners under NDA.
  • Clear data residency and retention documentation for project tenders.
  • A named security contact for incident coordination on multi-site installations.

OEM partners building on our platform inherit the same certified backbone, which means their own security questionnaires get shorter.

Security Is a Roadmap, Not a Certificate

The certificate is dated 2026, but the work continues. Over the coming year we are extending the management system to cover our partner portal, expanding hardware secure-element adoption across the DESF and DESO ranges, and publishing a simple security whitepaper for installers. If any of that matters to a project you are planning, our team is ready to talk; you will find everything you need on the about page. We will keep reporting progress here as each milestone lands.

How We Got Here: The Audit Year

Certification stories usually skip the unglamorous middle, so here is ours. The journey began with a full gap analysis against the standard, which produced a remediation list longer than anyone enjoyed reading. Over the following months we rewrote access policies, formalized change management for cloud releases, hardened backup procedures, and ran two full internal audits before the external certifying body ever arrived.

The final assessment combined documentation review, on-site interviews across engineering, operations, and IT, and sampling of live processes. Observations from the auditors were closed ahead of the certificate being issued, and every corrective action is tracked in the same register our management reviews quarterly.

A few milestones from the program:

  • Completed company-wide security awareness training for all staff with system access.
  • Formalized a vulnerability disclosure channel with defined response times.
  • Extended backup and recovery testing from annual spot checks to scheduled, documented drills.
  • Established supplier security clauses covering any partner that touches user data.

Questions We Are Happy to Answer

Over the years, customers and partners have asked us fair, direct questions about data practices, and certification does not make the questions go away; it just means our answers now have receipts. Where are face templates stored? On the lock, full stop. How long are access logs retained? As long as the account holder chooses, exportable and deletable in the app. Who can decrypt cloud backups? Only the account, by design. If your project needs answers phrased for a procurement questionnaire, our team will provide them in writing, and gladly.

One closing thought for readers weighing vendors. Certificates, audits, and policies are necessary, but the strongest security control any company has is a culture where engineers flag problems early and management actually wants to hear it. That culture does not fit on a certificate, yet every control on it depends on it. We will keep earning both.

Back to all perspectives