This document defines the scope of the Information Security Management System (ISMS) for ISMS Copilot, operated by Better ISMS (France). It identifies the…
This document defines the scope of the Information Security Management System (ISMS) for ISMS Copilot, operated by Better ISMS (France). It identifies the boundaries and applicability of the ISMS, considering our organizational context, interested parties, and interfaces with external services.
This scope document follows ISO 27001:2022 Clause 4.3 and is reviewed annually or when significant changes occur to our services, integrations, or organizational structure.
The ISMS applies to the development, operation, and management of the ISMS Copilot platform — a cloud-hosted, AI-powered SaaS application that assists organizations with information security management system compliance.
The ISMS boundary includes the management of interfaces with external entities:
End users connect via browsers to the Frontend (Vercel), which communicates with Supabase (DB/Auth/Storage/Edge Functions) and the Fly.io Chat Service
Fly.io Chat Service interfaces with AI Providers (Anthropic, OpenAI, xAI, Mistral, Gemini) and Supabase DB
Stripe and ConvertAPI are accessed via Supabase Edge Functions
GitHub Actions manages the CI/CD pipeline
Sentry, PostHog, and BetterStack provide monitoring and observability
All data at rest is stored within EU infrastructure (Frankfurt). The backend chat service runs in Paris (CDG). AI provider API calls may transit to non-EU endpoints, which is documented in our Transfer Impact Assessment.
This scope document is reviewed annually, when new services or integrations are added, when organizational structure changes, when entering new markets or jurisdictions, and following management review findings. Changes to the ISMS scope require CEO approval and trigger a review of the Statement of Applicability, risk assessment, and affected policies.