Security and quality, independently certified.
This page covers Layermark's certifications, the security controls in place across the company, and how Layermark handles client information in service delivery. Every certification can be checked against its certificate, and supporting documents are available on request.
Independent Certifications and Ratings
Details match the issued certificates and appraisal record. Each card lists the identifiers and dates needed to confirm it with the issuing body.
ISO/IEC 27001:2022
- Certificate
- ISMS-25.01.339
- Issuer
- DSR Certification and Inspection, LLC
- Issued
- April 28, 2026
- Scope
- “Software Development, and CMMI Training and Appraisal Services”
ISO 9001:2015
- Certificate
- QMS-25.01.339
- Issuer
- DSR Certification and Inspection, LLC
- Issued
- April 28, 2026
CMMI Development Maturity Level 2
- Record
- PARS appraisal 68133
- Type
- Benchmark appraisal
- Unit
- Software & Systems Product Development
- Appraised
- November 20, 2023
- Model
- CMMI Development, Maturity Level 2
Controls in Place
Every control listed is in place today. Layermark's information security management system is certified to ISO/IEC 27001:2022 for the scope stated on the certificate. These are company controls, not claims about specific products.
Security Governance
4 controls in place- Information security is managed under an information security management system certified to ISO/IEC 27001:2022.
- Company-wide information security policies, including privacy policies, are in place.
- Internal and third-party cloud deployments are managed under Layermark's information security management system.
- Layermark carries cybersecurity insurance.
Asset Management
4 controls in place- A regularly maintained asset management program for IT assets is approved by management.
- Documented hardware and software policies and practices ensure asset integrity.
- Backup and replacement hardware and software assets are inventoried and audited.
- Devices and software installed by users outside the IT function are discovered, secured and managed.
Access and Network Security
2 controls in place- Network access control policies and procedures for information systems are aligned with ISO/IEC 27001:2022.
- Hardening standards are in place for network devices, including firewalls and wireless access points.
Threat Detection
2 controls in place- Documented policies and procedures cover the identification and detection of cyber threats.
- Software running within the enterprise is scanned for vulnerabilities before acceptance.
Incident Response and Recovery
3 controls in place- Documented incident detection practices define the actions to take in a security event. Managed services that Layermark provides are actively monitored.
- A documented incident response process is supported by a dedicated incident response team.
- Recovery procedures for restoring full functionality after a major cybersecurity incident, including integrity verification, are documented.
Physical Security
2 controls in place- Documented policies and procedures restrict physical access to IT assets to personnel with a demonstrated need.
- Suspected or unauthorized physical access to information, systems or assets is handled under the documented incident response process.
Training and Conduct
3 controls in place- All personnel are trained in security practices, including insider threats, access control and data protection.
- Personnel with administrative rights or other elevated privileges complete additional cybersecurity training.
- A Code of Conduct applies to employees, suppliers and subcontractors.
Supplier Management
6 controls in place- An organization-wide strategy manages end-to-end supply chain risk, from acquisition through life-cycle support and disposal.
- The acquisition and use of third-party software is controlled under the information security management system.
- Supplier contracts include obligations to protect information and information systems, and written supply chain risk management requirements.
- Suppliers and third-party components are checked against banned lists.
- Prospective suppliers are evaluated for product integrity during selection.
- Third-party hardware and software products and services are monitored for defects.
Service Continuity
5 controls in place- Services are delivered remotely and do not depend on a single office, data center or network route. Working files are held on enterprise cloud services with geographically redundant storage and backup, kept separate for each client.
- If an assigned consultant becomes unavailable, Layermark assigns a substitute and informs the client.
- Clients are notified promptly, in writing, of any actual or anticipated event that could materially affect delivery.
- Clients are notified in advance of material changes that could affect delivery, including changes to assigned personnel, security policies or delivery method.
- At the end of an engagement, Layermark returns all client materials, provides a written list of open matters and cooperates in the transition.
Client information stays separate, access-controlled and never used to train AI.
Client information is handled only by the Layermark personnel assigned to the engagement, under Layermark's information security management system. The commitments below apply to all employees, contractors and subcontractors.
- Access
- Limited to the Layermark personnel assigned to the engagement
- Separation
- A separate working area for each client
- AI tools
- Client content is never used to train or improve any model, and never exposed to public or shared AI services
- Exit
- All client materials returned at the end of the engagement
Scope. Covers Layermark's handling of client information in delivering services to clients in the United States and other regions.
- 01
Separate Working Area per Client
Client information stays in a separate working area for each client, accessible only to the personnel assigned to the engagement.
- 02
Named Access Only
Files move through a private, access-controlled cloud collaboration site. Access goes to named email addresses only, with no anonymous or organization-wide links.
- 03
No Training on Client Data
Client information is never used to train or improve any AI model, and is never exposed to public or shared AI services.
- 04
Human Review Before Release
The engagement lead reviews and approves every client deliverable before it is released.
- 05
Prompt Incident Notification
Clients are notified promptly, in writing, of any event that could materially affect their information or the delivery of services.
- 06
Return at End of Engagement
At the end of an engagement, Layermark returns all client materials and provides a written list of open matters.
Evidence for Reviewers
Request Access opens a pre-filled email to trust-center@layermark.com. Include your organization and the purpose of your review.
ISO/IEC 27001:2022 Certificate
On RequestPrivacy Policy
PublicUsed in Service Delivery
Third parties that may handle client information when Layermark delivers services. Product subprocessors are not covered.
AI model provider
United StatesMicrosoft Corporation
Questions Reviewers Ask
Answers draw only on the certifications and controls above.
Is Layermark certified to ISO/IEC 27001?
Yes. Layermark holds ISO/IEC 27001:2022 certificate no. ISMS-25.01.339, issued by DSR Certification and Inspection, LLC. The certificate was issued April 28, 2026.
What does the ISO/IEC 27001 certification cover?
The certificate scope is “Software Development, and CMMI Training and Appraisal Services.”
What other certifications or ratings does Layermark hold?
Layermark holds ISO 9001:2015 certificate no. QMS-25.01.339 from the same issuer. Layermark, Inc. was appraised at CMMI Development Maturity Level 2 in a Benchmark appraisal completed on November 20, 2023 (PARS appraisal 68133).
Is client information used to train AI models?
No. Layermark does not use client information to develop, train or improve any product, tool or model, and client information is never exposed to public or shared AI services. Provider commercial terms exclude the use of customer content for training.
Who reviews work before it reaches a client?
Every document Layermark issues to a client is reviewed and approved by the Layermark engagement lead before release.
How is our information kept separate from other clients' information?
Client information is held in a separate working area for each client that only the Layermark personnel assigned to the engagement can access. Files are exchanged through a private, access-controlled cloud collaboration site, with access granted to named email addresses only.
Will Layermark notify us of disruptions or material changes?
Yes. Layermark notifies clients promptly, in writing, of events that could materially affect delivery, and notifies them in advance of material changes to assigned personnel, security policies or delivery method.
How do I report a security vulnerability or concern?
Email trust-center@layermark.com. Reports are handled under Layermark's documented incident response process.
Does this page cover Layermark products such as LayerExchange or LayerChat?
No. This page covers company controls and service delivery. For product security questions, contact trust-center@layermark.com.
Contact and Security Reporting
Layermark · 1050 Connecticut Ave NW, Suite 500, Washington, DC 20036Request Documents
Email trust-center@layermark.com with your organization and the documents you need.
Report a Security Concern
Email trust-center@layermark.com to report a vulnerability or security concern. Reports are handled under Layermark's documented incident response process.