ISO 27001 & GDPR Alignment
This overview explains how TheOS's described architecture can support information security and data protection objectives, and what must be assessed for each deployment. It covers TheOS, the product built by Starkien Pty Ltd.
1. Status and scope
Starkien is not currently ISO/IEC 27001 certified. This page does not represent an independent audit, a completed assessment of conformity, or a guarantee of GDPR compliance.
The capabilities below describe the product approach. Their availability and effectiveness depend on the deployed version, configuration, connected services and operating procedures. They must be checked against deployment evidence. Marketing descriptions alone do not establish that a control is implemented or effective.
2. ISO/IEC 27001 alignment approach
ISO/IEC 27001:2022 concerns an information security management system, including organizational risk management and continual improvement. Software controls can support that system, but do not establish conformity on their own. See the official ISO overview.
For Starkien, a substantiated alignment assessment would need a defined scope, risk assessment, risk treatment plan, Statement of Applicability, assigned responsibilities and evidence of operating controls. Internal audits, management review and corrective action also require organizational evidence. This page does not assert that those activities are complete.
Identity and access
TheOS is described as supporting roles, permissions and governance boundaries. These capabilities can support controlled access. A deployment review should verify permission enforcement, privileged access, account removal and isolation between workspaces, including negative tests for unauthorized access.
Automation and change control
Published workflows, approval gates and execution records can support controlled automation. Review which actions require approval, who can change or publish workflows, how changes are recorded and how failures are handled. An approval feature is effective only when configured and enforced for the relevant action.
Data movement and integrations
Customer-managed resources and configurable AI or service connections can support control over processing destinations. Review actual data flows, credentials, provider selection, outbound requests and logging. A private or BYO deployment does not by itself prove that no data leaves the customer's environment.
Traceability and execution boundaries
Execution records and governance controls can support investigations and accountability. Review log coverage, integrity, access and retention. Where isolated execution is offered, verify the actual isolation mode and resource restrictions. This document makes no blanket claim about encryption coverage, penetration testing or independently verified isolation.
3. GDPR responsibilities
Where the GDPR applies, responsibilities depend on the purpose and circumstances of processing. Customers generally act as controllers for personal data processed through TheOS on their instructions; Starkien acts as a processor for that processing. Starkien may act as a controller for its own website, business contacts and account administration. The Data Processing Agreement and Privacy Policy describe these different contexts.
Lawfulness and privacy by design
GDPR Articles 5, 6 and 25 address processing principles, lawful bases and data protection by design and default. Permissions and configurable workflows can support these objectives. Controllers must still establish an appropriate lawful basis, provide required notices and choose proportionate collection, access and retention settings. Product settings cannot determine lawfulness on their own.
Processor arrangements and security
Articles 28 and 32 address processor arrangements and security appropriate to risk. Assessment should cover documented instructions, applicable contractual terms, sub-processors and technical and organizational measures. BYO configurations divide operational tasks but do not remove either party's applicable legal obligations.
Individual rights and retention
Procedures for applicable rights under Articles 12 to 22 must account for data in TheOS, integrations, logs and backups. Access, correction, export or deletion should be tested across the relevant processing chain. This page does not claim universal automated rights fulfilment or immediate deletion from all connected systems.
Incidents, high-risk processing and transfers
Articles 33 and 34 distinguish processor notification to the controller from the controller's applicable notification duties. Incident responsibilities and escalation paths must be established. Article 35 may require a data protection impact assessment for high-risk processing; human approval controls alone do not resolve all automated decision-making obligations. International transfers must be assessed under Chapter V, including remote access and connected providers, even when primary hosting is local.
4. AI and customer-managed resources
Starkien's stated approach is that customer personal data is not used to train shared or global AI models by default, as described in the Security & Compliance Overview. For each deployment, verify model-provider terms, retention settings, destinations and any separate training agreement. Third-party provider practices must be assessed independently.
Customers are responsible for the resources they control, including credentials, cloud accounts and connected services. Starkien remains responsible for its own processing and managed components under applicable law and agreement. The actual boundary should be documented before deployment.
5. Evidence for a deployment review
A review should establish which controls are implemented, which are customer-configured and which remain outstanding. Relevant evidence includes:
- The system scope, data-flow inventory and security risk assessment.
- Access-control tests, change records and logging configuration.
- Incident procedures, backup arrangements and restoration test results.
- Processing records where required, retention rules and tested rights procedures.
- Sub-processor details, contractual safeguards and transfer assessments.
- Any required impact assessments and records of unresolved risks.
This list identifies review topics. It is not a claim that every document, test or assurance report is currently available.
6. Questions and references
For questions about a proposed deployment or the availability of supporting evidence, contact support@starkien.com.
References: ISO/IEC 27001:2022 and the official GDPR text. The GDPR references above identify relevant assessment areas, not an exhaustive legal mapping.
This overview is informational and does not amend the applicable agreement or constitute certification. Specific commitments are governed by the agreed contractual documents and applicable law.
← All compliance documents