RedStone Is ISO/IEC 27001:2022 Certified
RedStone Secures an ISO/IEC 27001:2022 Certificate
RedStone has completed an independent audit and been issued a certificate of compliance with ISO/IEC 27001:2022, the international standard for information security management systems (ISMS). The standard provides a systematic framework for identifying, assessing, and managing information security risks, covering areas such as access control, data protection, incident response, and ongoing monitoring.
The certificate was issued by SGS United Kingdom Ltd, an internationally accredited certification body, on August 28, 2026. It is valid through August 27, 2029, with the certification status currently active.
What the Certification Covers
The scope of RedStone’s ISO 27001 certificate is specific to the design, development, maintenance, and management of RedStone services infrastructure used to provide: acquisition from suppliers or public sources, processing, and delivery of external price quotations of digital and traditional assets (off-chain) to blockchain networks (onchain) and via web applications and APIs, together with data validation, indexing, aggregation, signing, and distribution processes, the lifecycle of smart contracts mediating data transfers, and cryptographic key management.
RedStone services include: node, relayer, gateway, monitoring and alerting, Proof of Reserve of digital assets, and hosting systems located in external cloud resources.
A Formal Standard for an Existing Discipline
The certificate is new, but the practice beneath it is anything but. RedStone has run redundancy across infrastructure providers for years rather than depend on a single point of failure, a discipline documented in how it structures RPC and node access across 110+ chains.
That same operational posture showed up under real pressure in May 2026, when RedStone became the official price data provider for Kraken’s Ink Layer 2 after Ink’s previous provider faced a suspected nation-state-level attack. RedStone went from initial contact to live production feeds in under 48 hours, without compromising on security or reliability.
RedStone’s price feeds already sit underneath a meaningful share of onchain institutional finance. Through its partnership with Securitize, RedStone is the primary data layer for tokenized funds from BlackRock (BUIDL), Apollo (ACRED), and Hamilton Lane (SCOPE). It provides the daily NAV calculations behind VanEck’s VBILL, a tokenized US Treasury fund.
ISO 27001 certification adds a formal, independently audited framework to the discipline the company has shown for years. It gives asset managers a recognized, independently audited reference point.
Need a copy? RedStone provides the certificate and an audit summary on request.
Frequently Asked Questions
What is ISO/IEC 27001:2022?
ISO/IEC 27001:2022 is the international standard for information security management systems (ISMS). It defines a systematic framework for identifying, assessing, and managing information security risks across areas such as access control, data protection, incident response, and ongoing monitoring.
What does RedStone’s ISO 27001 certificate cover?
The certificate covers the design, development, maintenance, and management of the infrastructure behind RedStone’s core services: acquiring, processing, and delivering price data across offchain and onchain systems, the data validation and signing pipeline, smart contract lifecycle management, cryptographic key management, and the node, relayer, gateway, monitoring, and hosting infrastructure behind it.
Who issued RedStone’s certificate, and how long is it valid?
SGS United Kingdom Ltd, an internationally accredited certification body, issued the certificate on August 28, 2026. It is valid through August 27, 2029. As with any ISO 27001 certification, maintaining it over that three-year cycle requires ongoing conformity with the standard, not a one-time review.