ISMS Copilot Docs

ISMS Scope

This document defines the scope of the Information Security Management System (ISMS) for ISMS Copilot, operated by Better ISMS (France). It identifies the…

This document defines the scope of the Information Security Management System (ISMS) for ISMS Copilot, operated by Better ISMS (France). It identifies the boundaries and applicability of the ISMS, considering our organizational context, interested parties, and interfaces with external services.

This scope document follows ISO 27001:2022 Clause 4.3 and is reviewed annually or when significant changes occur to our services, integrations, or organizational structure.

Organization

FieldValue
Legal EntityBetter ISMS
JurisdictionFrance (EU)
ProductISMS Copilot — AI-powered compliance assistant
Business ModelB2B SaaS (subscription-based)
Users~800 (primarily EU-based, globally available)

ISMS Scope Statement

The ISMS applies to the development, operation, and management of the ISMS Copilot platform — a cloud-hosted, AI-powered SaaS application that assists organizations with information security management system compliance.

Applications and Services in Scope

ComponentTechnologyHosting
Frontend web applicationReact, TypeScript, ViteVercel (global CDN)
Backend chat serviceDeno, TypeScriptFly.io (CDG region, Paris)
Database and authenticationPostgreSQL, Supabase AuthSupabase Cloud (EU — Frankfurt)
File storageS3-compatibleSupabase Storage (EU — Frankfurt)
Edge functionsDenoSupabase Edge

Third-Party Integrations in Scope

IntegrationPurposeScope Coverage
Anthropic (Claude)Default AI chat providerData flows, key management, provider monitoring
OpenAI (GPT-4.1)Document detectionData flows, key management
xAI (Grok)Document formattingData flows, key management
Mistral AIAdvanced Data Protection modeData flows, key management, ZDR verification
Google (Gemini)Alternative AI chat providerData flows, key management
StripePayment processingWebhook security, subscription management
ConvertAPIFile conversion (PDF, DOCX, XLSX)Data flows, file handling
SendGridSecurity alert emailsAlert delivery

Data in Scope

Data CategoryIn Scope
User chat messages and AI responsesYes
Uploaded files and extracted contentYes
User account and authentication dataYes
Subscription and billing metadataYes
User settings and workspace instructionsYes
Token consumption and usage recordsYes
Application logs and error reportsYes

Processes in Scope

ProcessIn Scope
Software development lifecycle (SDLC)Yes
Change management and deploymentYes
Incident detection, response, and recoveryYes
Risk assessment and treatmentYes
Access management and reviewYes
Vulnerability managementYes
Supplier managementYes
Data protection and privacyYes
Business continuity and disaster recoveryYes

Monitoring and Development Tools in Scope

ToolPurposeScope Coverage
SentryError tracking (frontend + backend)PII scrubbing, log hygiene
PostHogProduct analyticsData minimization
BetterStackUptime monitoring, status pageAlert configuration
GitHubSource code, CI/CD pipelinesAccess control, secrets management, pipeline security
Vercel CI/CDFrontend deploymentDeployment security

Exclusions from Scope

ExclusionJustification
Physical office infrastructureTeam is fully remote; no physical office to secure
Employee personal devicesBYOD environment; security controls are at the application and platform layer, not endpoint
Customer-side securityCustomer environments, endpoints, and internal networks are outside ISMS Copilot's control
Third-party internal operationsSupplier internal security is governed by their own certifications (SOC 2, ISO 27001) and our supplier management policy
Marketing websiteStatic marketing site on separate infrastructure; no user data processing

ISMS Boundary Diagram

The ISMS boundary includes the management of interfaces with external entities:

  • End users connect via browsers to the Frontend (Vercel), which communicates with Supabase (DB/Auth/Storage/Edge Functions) and the Fly.io Chat Service
  • Fly.io Chat Service interfaces with AI Providers (Anthropic, OpenAI, xAI, Mistral, Gemini) and Supabase DB
  • Stripe and ConvertAPI are accessed via Supabase Edge Functions
  • GitHub Actions manages the CI/CD pipeline
  • Sentry, PostHog, and BetterStack provide monitoring and observability

All data at rest is stored within EU infrastructure (Frankfurt). The backend chat service runs in Paris (CDG). AI provider API calls may transit to non-EU endpoints, which is documented in our Transfer Impact Assessment.

Applicable Standards and Frameworks

StandardScope of Application
ISO/IEC 27001:2022Full ISMS — all clauses and applicable Annex A controls
ISO/IEC 42001:2023AI Management System — applicable to AI components
GDPRAll personal data processing activities
SOC 2Trust Services Criteria — Security, Availability, Confidentiality
French Data Protection LawNational GDPR implementation

Scope Review

This scope document is reviewed annually, when new services or integrations are added, when organizational structure changes, when entering new markets or jurisdictions, and following management review findings. Changes to the ISMS scope require CEO approval and trigger a review of the Statement of Applicability, risk assessment, and affected policies.

On this page