Plainly put
The standards we measure ourselves against
We are not certified ourselves.
ISO/IEC 27001 + ISO/IEC 27018
Information security · certifiable, and we are not
ISO/IEC 27001 + ISO/IEC 27018
Information security · certifiable, and we are not
- What the standard asks for
- ISO/IEC 27001 asks for a systematic way of handling information risk. Identify it, judge it, secure it, keep it under review. ISO/IEC 27018 adds the protection of personal data wherever a public cloud processes it.
- What we actually do
- We keep the amount of data that can reach us in the first place small. The app computes on your device, no upload of your process data, no account, no sync. Whatever cannot be avoided technically is cut back to the bare minimum, runs without cookies and without stored IP addresses, and only through processors that are themselves certified against these standards. That is the heart of both standards, boiled down to one rule. The less that sits anywhere, the less can be lost there.
- What we do not claim
- We do not run a certified information security management system. It is the providers we rely on that hold the certificates, not us.
ISO 9001
Quality management · certifiable, and we are not
ISO 9001
Quality management · certifiable, and we are not
- What the standard asks for
- ISO 9001 asks you to see the business as a chain of processes, to describe and measure each one, and to improve it through the cycle of plan, do, check, act. Demonstrably, not just on paper.
- What we actually do
- Every change takes the same route. Requirement, build, check, release. The check is automated, and it is a gate, not advice. If it fails, nothing ships. We do not patch faults at the surface, we trace them back to their cause so the same fault does not happen twice. The cycle the standard asks for is the very cycle our method teaches. We would cut a poor figure selling it and not living it.
- What we do not claim
- We are not certified to ISO 9001 and hold no certificate. We work to the principles of the standard, and we claim nothing beyond that.
ISO/IEC 12207
Software life cycle · reference model, cannot be certified against
ISO/IEC 12207
Software life cycle · reference model, cannot be certified against
- What the standard asks for
- ISO/IEC 12207 sets out the processes that accompany a piece of software through its whole life, from requirement through design, build and test to maintenance, care and retirement.
- What we actually do
- No feature exists because it felt nice. First comes what it has to achieve and how we will know it does. Then the build, then the test, then the release. Work does not stop at the release. Maintenance, fixes and further development are planned for, not merely tolerated. That is the point of the standard, because most of the cost of a piece of software arrives after day one.
- What we do not claim
- There is no certification for this standard. It is a reference model, not a mark of approval. Nobody can be certified against it, so neither can we.
ISO/IEC 25010
Software quality · reference model, cannot be certified against
ISO/IEC 25010
Software quality · reference model, cannot be certified against
- What the standard asks for
- ISO/IEC 25010 breaks the vague word quality into characteristics you can actually test. Functional suitability, performance, compatibility, usability, reliability, security, maintainability and adaptability.
- What we actually do
- The characteristics of the standard are our yardstick, not our gut feeling. Reliability, to us, means the app runs with no network, even in the basement of a plant. Usability means whoever opens it for the first time gets by without training, in any of 33 languages. Adaptability means the same application runs in the browser, on the desktop and on a phone. If you want quality you can measure, you need sentences like these, not adjectives.
- What we do not claim
- This standard, too, is a reference model and cannot be certified against. We measure ourselves by its characteristics; we carry no mark of approval.
ISO 14001
Environmental management · certifiable, and we are not
ISO 14001
Environmental management · certifiable, and we are not
- What the standard asks for
- ISO 14001 asks you to know your environmental impact, to steer it and to reduce it step by step. Again as a cycle, again demonstrably.
- What we actually do
- Two things we can back up today. First, what runs without a network consumes no data centre. Our app computes on your device, not on a server drawing power around the clock. Second, and this weighs more. The work itself lowers consumption. Waste is not only time. It is material that ends up as scrap. It is journeys nobody needed to make. It is stock nobody needs. Make that visible and stop it, and you save resources before they are spent. That is the idea behind the standard, at the root, not at the end of the chain.
- What we do not claim
- We are only now building an environmental management system of our own. We are not certified to ISO 14001, we keep no environmental balance sheet, and we claim neither carbon neutrality nor any other environmental award. What stands here is where we are today, no more.
Questions before we work together?
If your procurement or quality management wants to know more, ask us directly. We will answer with what we can back up.
Get in touchStandard designations are used descriptively. ISO/IEC 12207 and ISO/IEC 25010 are reference models and cannot be certified. Lean Shift is neither endorsed nor authorised by ISO.
As of July 2026. When our position changes, this page changes.