Skip to content
Layermark Trust Center

Security and quality, independently certified.

This page covers Layermark's certifications, the security controls in place across the company, and how Layermark handles client information in service delivery. Every certification can be checked against its certificate, and supporting documents are available on request.

Certifications

Independent Certifications and Ratings

Details match the issued certificates and appraisal record. Each card lists the identifiers and dates needed to confirm it with the issuing body.

Information SecurityValid

ISO/IEC 27001:2022

Certificate
ISMS-25.01.339
Issuer
DSR Certification and Inspection, LLC
Issued
April 28, 2026
Scope
“Software Development, and CMMI Training and Appraisal Services”
Quality ManagementValid

ISO 9001:2015

Certificate
QMS-25.01.339
Issuer
DSR Certification and Inspection, LLC
Issued
April 28, 2026
Process MaturityRated

CMMI Development Maturity Level 2

Record
PARS appraisal 68133
Type
Benchmark appraisal
Unit
Software & Systems Product Development
Appraised
November 20, 2023
Model
CMMI Development, Maturity Level 2
Controls

Controls in Place

Every control listed is in place today. Layermark's information security management system is certified to ISO/IEC 27001:2022 for the scope stated on the certificate. These are company controls, not claims about specific products.

Security Governance

4 controls in place
  • Information security is managed under an information security management system certified to ISO/IEC 27001:2022.
  • Company-wide information security policies, including privacy policies, are in place.
  • Internal and third-party cloud deployments are managed under Layermark's information security management system.
  • Layermark carries cybersecurity insurance.

Asset Management

4 controls in place
  • A regularly maintained asset management program for IT assets is approved by management.
  • Documented hardware and software policies and practices ensure asset integrity.
  • Backup and replacement hardware and software assets are inventoried and audited.
  • Devices and software installed by users outside the IT function are discovered, secured and managed.

Access and Network Security

2 controls in place
  • Network access control policies and procedures for information systems are aligned with ISO/IEC 27001:2022.
  • Hardening standards are in place for network devices, including firewalls and wireless access points.

Threat Detection

2 controls in place
  • Documented policies and procedures cover the identification and detection of cyber threats.
  • Software running within the enterprise is scanned for vulnerabilities before acceptance.

Incident Response and Recovery

3 controls in place
  • Documented incident detection practices define the actions to take in a security event. Managed services that Layermark provides are actively monitored.
  • A documented incident response process is supported by a dedicated incident response team.
  • Recovery procedures for restoring full functionality after a major cybersecurity incident, including integrity verification, are documented.

Physical Security

2 controls in place
  • Documented policies and procedures restrict physical access to IT assets to personnel with a demonstrated need.
  • Suspected or unauthorized physical access to information, systems or assets is handled under the documented incident response process.

Training and Conduct

3 controls in place
  • All personnel are trained in security practices, including insider threats, access control and data protection.
  • Personnel with administrative rights or other elevated privileges complete additional cybersecurity training.
  • A Code of Conduct applies to employees, suppliers and subcontractors.

Supplier Management

6 controls in place
  • An organization-wide strategy manages end-to-end supply chain risk, from acquisition through life-cycle support and disposal.
  • The acquisition and use of third-party software is controlled under the information security management system.
  • Supplier contracts include obligations to protect information and information systems, and written supply chain risk management requirements.
  • Suppliers and third-party components are checked against banned lists.
  • Prospective suppliers are evaluated for product integrity during selection.
  • Third-party hardware and software products and services are monitored for defects.

Service Continuity

5 controls in place
  • Services are delivered remotely and do not depend on a single office, data center or network route. Working files are held on enterprise cloud services with geographically redundant storage and backup, kept separate for each client.
  • If an assigned consultant becomes unavailable, Layermark assigns a substitute and informs the client.
  • Clients are notified promptly, in writing, of any actual or anticipated event that could materially affect delivery.
  • Clients are notified in advance of material changes that could affect delivery, including changes to assigned personnel, security policies or delivery method.
  • At the end of an engagement, Layermark returns all client materials, provides a written list of open matters and cooperates in the transition.
Responsible Data Handling

Client information stays separate, access-controlled and never used to train AI.

Client information is handled only by the Layermark personnel assigned to the engagement, under Layermark's information security management system. The commitments below apply to all employees, contractors and subcontractors.

Access
Limited to the Layermark personnel assigned to the engagement
Separation
A separate working area for each client
AI tools
Client content is never used to train or improve any model, and never exposed to public or shared AI services
Exit
All client materials returned at the end of the engagement

Scope. Covers Layermark's handling of client information in delivering services to clients in the United States and other regions.

  1. 01

    Separate Working Area per Client

    Client information stays in a separate working area for each client, accessible only to the personnel assigned to the engagement.

  2. 02

    Named Access Only

    Files move through a private, access-controlled cloud collaboration site. Access goes to named email addresses only, with no anonymous or organization-wide links.

  3. 03

    No Training on Client Data

    Client information is never used to train or improve any AI model, and is never exposed to public or shared AI services.

  4. 04

    Human Review Before Release

    The engagement lead reviews and approves every client deliverable before it is released.

  5. 05

    Prompt Incident Notification

    Clients are notified promptly, in writing, of any event that could materially affect their information or the delivery of services.

  6. 06

    Return at End of Engagement

    At the end of an engagement, Layermark returns all client materials and provides a written list of open matters.

Documents

Evidence for Reviewers

Request Access opens a pre-filled email to trust-center@layermark.com. Include your organization and the purpose of your review.

ISO/IEC 27001:2022 Certificate

On Request
Certificate no. ISMS-25.01.339 · DSR Certification and Inspection, LLC

Privacy Policy

Public
Published on layermark.com
Subprocessors

Used in Service Delivery

Third parties that may handle client information when Layermark delivers services. Product subprocessors are not covered.

AI model provider

United States
Commercial AI service used under terms that exclude client content from training. Provider identified to clients on request.

Microsoft Corporation

Microsoft 365: cloud-hosted working files, collaboration and access-controlled file exchange
FAQ

Questions Reviewers Ask

Answers draw only on the certifications and controls above.

Is Layermark certified to ISO/IEC 27001?

Yes. Layermark holds ISO/IEC 27001:2022 certificate no. ISMS-25.01.339, issued by DSR Certification and Inspection, LLC. The certificate was issued April 28, 2026.

What does the ISO/IEC 27001 certification cover?

The certificate scope is “Software Development, and CMMI Training and Appraisal Services.”

What other certifications or ratings does Layermark hold?

Layermark holds ISO 9001:2015 certificate no. QMS-25.01.339 from the same issuer. Layermark, Inc. was appraised at CMMI Development Maturity Level 2 in a Benchmark appraisal completed on November 20, 2023 (PARS appraisal 68133).

Is client information used to train AI models?

No. Layermark does not use client information to develop, train or improve any product, tool or model, and client information is never exposed to public or shared AI services. Provider commercial terms exclude the use of customer content for training.

Who reviews work before it reaches a client?

Every document Layermark issues to a client is reviewed and approved by the Layermark engagement lead before release.

How is our information kept separate from other clients' information?

Client information is held in a separate working area for each client that only the Layermark personnel assigned to the engagement can access. Files are exchanged through a private, access-controlled cloud collaboration site, with access granted to named email addresses only.

Will Layermark notify us of disruptions or material changes?

Yes. Layermark notifies clients promptly, in writing, of events that could materially affect delivery, and notifies them in advance of material changes to assigned personnel, security policies or delivery method.

How do I report a security vulnerability or concern?

Email trust-center@layermark.com. Reports are handled under Layermark's documented incident response process.

Does this page cover Layermark products such as LayerExchange or LayerChat?

No. This page covers company controls and service delivery. For product security questions, contact trust-center@layermark.com.

Contact and Security Reporting

Layermark · 1050 Connecticut Ave NW, Suite 500, Washington, DC 20036

Request Documents

Email trust-center@layermark.com with your organization and the documents you need.

Report a Security Concern

Email trust-center@layermark.com to report a vulnerability or security concern. Reports are handled under Layermark's documented incident response process.