ISO/IEC 27001 Certified
Information Security Management System (ISMS) — International Organization for Standardization
1.1ISO/IEC 27001 is the internationally recognised standard for Information Security Management Systems (ISMS). Published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC), it specifies a systematic framework for identifying, managing, and reducing information security risks.
1.2Certification is awarded by an accredited third-party certification body following an independent audit of the organisation's security policies, processes, controls, and technical infrastructure. Certification is maintained through annual surveillance audits and a full re-certification audit every three years.
1.3ISO/IEC 27001 is the gold standard for information security in legal services technology, aligning with requirements from law firm clients, regulators, and professional indemnity insurers across Australia, the United Kingdom, and internationally.
2.1The 3Rive Technologies ISO/IEC 27001 certification covers the design, development, delivery, and support of legal technology and managed services across all four group entities:
3Rive Technologies Pty Ltd — Melbourne, Australia
Group headquarters and primary client engagement entity for Australian and New Zealand law firms.
3Rive Technologies Ltd — London, United Kingdom
UK entity serving British and Irish law firms, including Top 100 UK firms and international practices.
3Rive Technologies FZ LLC — Dubai, UAE
Dubai Free Zone holding entity. ISMS controls applied across group governance and information assets.
3Rive Technologies (Pvt) Ltd — Colombo, Sri Lanka
Group delivery centre. All personnel and systems operate within the certified ISMS scope.
2.2The certification scope covers the provision of AI implementation, software development, data engineering, legal process outsourcing, technology advisory, and managed services to law firms and enterprise clients.
3.1ISO/IEC 27001 certification means 3Rive Technologies has implemented a documented and independently audited set of controls covering: information asset management, access control, cryptography, physical and environmental security, operations security, communications security, supplier relationships, incident management, business continuity, and compliance.
3.2All personnel with access to client data receive annual security awareness training. Access to client systems and data is granted on a least-privilege basis and reviewed periodically.
3.3Client data is encrypted at rest and in transit. Our cloud infrastructure providers (AWS, Microsoft Azure) are themselves ISO/IEC 27001 certified and operate within the scope of our sub-processor agreements.
3.4In the event of a security incident affecting client data, our incident response procedure specifies documented escalation paths, notification timelines, and post-incident review obligations consistent with applicable data protection law.
4.1Clients and prospective clients may request a copy of our current ISO/IEC 27001 certificate of conformity, Statement of Applicability (SoA), or summary security assessment by contacting us at the address below.
4.2Our certification body is an accredited third-party auditor. Certificate details including the issuing body, certificate number, and scope statement are available on request.
4.3For further verified facts about 3Rive Technologies — including our offices, leadership, certifications, and partner networks — see our Facts page.
5.1What is ISO/IEC 27001?
ISO/IEC 27001 is the leading international standard for information security management. It requires organisations to systematically identify information security risks, implement controls to address those risks, and maintain those controls through a cycle of audit, review, and improvement.
5.2Does the certification cover 3Rive's offshore delivery teams?
Yes. Our Sri Lanka delivery centre (3Rive Technologies (Pvt) Ltd) operates within the full scope of the certified ISMS. All personnel, systems, and processes in Colombo are subject to the same security controls as our Melbourne and London entities.
5.3How does ISO 27001 certification align with GDPR and Australian Privacy Act obligations?
While ISO/IEC 27001 certification is not a substitute for GDPR or Privacy Act compliance, the ISMS controls directly support compliance with the security requirements under Article 32 of the GDPR (technical and organisational measures) and the security obligations under the Australian Privacy Principles (APP 11). Our Data Processing Agreements reference the certified ISMS as evidence of appropriate technical and organisational measures.
5.4How can I verify that 3Rive's certification is current?
You can request a copy of the current certificate directly from us. Certificates include an expiry date and the name of the issuing certification body, whose accreditation can be independently verified through the relevant national accreditation body (e.g., UKAS in the UK, JAS-ANZ in Australia).
6.1For security-related enquiries, certificate requests, or to discuss our information security controls in the context of a client engagement, please contact:
Email: security@3rivetech.com
Further verified company facts are available at our Facts page.