Skip to main content
Contact Us

Contact Support

You are an existing client and require assistance, we got you covered :

MAIL US:
Support@OrNsoft.com
CALL US 24/7:
+ 1888 - 808 9498

Trust

AboutTrust & Compliance

OrNsoft Corporation has built software for enterprise, government and international organisations since 2009. This page sets out what we are certified for, what we commit to contractually, and how each of those claims can be verified independently — without having to take our word for it.

Our AchievementAccredited certifications

Independently audited · Third-party verifiable

ISO 9001:2015 — Quality Management System

Active
Certified entity OrNsoft Corporation
10800 Biscayne Boulevard, Suite 988, Miami, Florida 33161-7490, USA
Standard ISO 9001:2015
Certificate number IQ-24051002
Scope AI and Machine Learning solutions; development of customised software, web and mobile applications; AI document management and process automation; IT consulting services.
Certification body Intercontinental Systemcert Pvt. Ltd. (ISPL Cert)
Formerly Indraprastha Systemcert Pvt. Ltd. — the name shown on the original certificate PDF.
Accreditation body Egyptian Accreditation Council (EGAC), CAB no. 012205 — IAF MLA signatory
Issued 10 May 2024
Valid through 9 May 2027 — annual surveillance audits
IAF CertSearch status Active — registry last updated 13 August 2026

ISO/IEC 27001:2022 — Information Security Management System

Active
Certified entity OrNsoft Corporation
10800 Biscayne Boulevard, Suite 988, Miami, Florida 33161-7490, USA
Standard ISO/IEC 27001:2022 (current revision — transition from the 2013 edition completed)
Certificate number II-24051001
Statement of Applicability OC-SOA version 1.0, dated 10 November 2023
Scope Information Security Management System covering AI and Machine Learning solutions, development of customised software, web and mobile applications, AI document management and process automation, and IT consulting services, delivered from the Miami site.
Sites in scope Single main site — Miami, Florida
Certification body Intercontinental Systemcert Pvt. Ltd. (ISPL Cert)
Formerly Indraprastha Systemcert Pvt. Ltd.
Accreditation body Egyptian Accreditation Council (EGAC), CAB no. 012205 — IAF MLA signatory
Issued 10 May 2024
Valid through 9 May 2027 — annual surveillance audits
IAF CertSearch status Active — registry last updated 13 August 2026

How to verify these certifications

Both certificates are listed in IAF CertSearch, the global database of accredited certifications operated by the International Accreditation Forum. Verification does not depend on anything we publish:

Chain of accreditation

OrNsoft Corporation → Intercontinental Systemcert Pvt. Ltd. → Egyptian Accreditation Council (EGAC, CAB no. 012205) → International Accreditation Forum. EGAC is a signatory to the IAF Multilateral Recognition Arrangement, under which certificates issued through any signatory accreditation body are recognised as equivalent across all signatory economies. Every link in that chain is listed above and can be checked independently.

Data protection and contractual commitments

Contractual undertakings · Not third-party certifications

Your data is never used for our benefit

We do not use client data, documents or content to train, fine-tune or evaluate models for our own products, for other clients, or for resale — ever. Where an engagement involves training a model on your data, it is because you instructed us to, the resulting model is built for your use, and it is covered by the terms of your agreement. There is no secondary use.

Repository and infrastructure access

Continuous access to the source repository during development — rather than a hand-over at the end — is available and is set out in the statement of work. Where practical, production infrastructure runs in your own cloud account with your organisation holding the root and administrative credentials. If either matters to you, raise it during scoping and we will write it into the agreement.

Security practices

Access control, encryption in transit and at rest, logging, vulnerability management, backup and recovery, and incident notification are governed by the policies maintained under our ISO/IEC 27001 management system. Detailed policy documents are available under NDA as part of a vendor security review.

Confidentiality

Most of our client work is covered by non-disclosure agreements. We identify a client or a project publicly only where that client has authorised the disclosure. Where a reference cannot be named, we can arrange a direct reference call under NDA instead.

Intellectual property — stated up front, not after signature

Our default is that you own the work product: source code, database schemas, documentation, deployment scripts, configuration, project-specific models and prompts, designs and test suites. Two alternatives exist, and both are priced accordingly and agreed before the statement of work is signed — never assumed:
Reduced fee, retained IP. Where you do not need exclusive ownership, we can reduce the engagement price in exchange for retaining rights in the work.
Proprietary core. Where our existing platform components fit your requirement, building on them is significantly faster and cheaper than building from scratch. Those components remain ours and are licensed to you; everything built on top for your project follows the ownership terms of your agreement.
Whichever applies, the statement of work identifies every pre-existing OrNsoft component in the deliverable by name, together with its licence terms.

International data transfers

Transfers of personal data out of the European Economic Area are governed by the European Commission's Standard Contractual Clauses. Our Privacy Policy sets out the categories of data processed, retention periods and data subject rights. We maintain a standard Data Processing Agreement, provided on request for any engagement involving personal data.

On GDPR and HIPAA.

No organisation can be "GDPR certified" or "HIPAA certified" — no such certification scheme exists. We describe our position on both as what it is: a set of contractual and technical commitments, documented above and in our Privacy Policy, which we will evidence in a vendor assessment.

Registrations and identifiers
Available on request

For procurement, security review or vendor onboarding, we provide within one business day:

  • ISO/IEC 27001 Statement of Applicability and detailed ISMS scope
  • Most recent surveillance audit report
  • Information security, access management and incident response policies
  • Standard Master Services Agreement, Data Processing Agreement and NDA templates
  • Certificates of insurance
  • Named client references, including engagements running longer than 12 months
  • Named CVs of the specific team proposed for your engagement

Contact: compliance@ornsoft.com

Virtual Tour of
our Office

OrNsoft Office2

Ready to get started? Talk to us today!

Our highly skilled and experienced team would love to talk with you about your plans for digital domination.

For a FREE, confidential consultation on your big idea, simply leave your details here, and we’ll be in touch ASAP.

Form Decoration
Send Us a Message
Messages are related to my inquiry, consultation request, demo request, support request, account communication, or partner application. Message frequency varies and may be up to 10 messages per month. Message and data rates may apply. Reply STOP to opt out or HELP for help. Consent is not required to purchase, license, or use any OrNsoft product or service.