Trust & compliance

Security you can verify.

altovo (formerly easygds) achieved SOC 2 Type 2 and ISO/IEC 27001:2022 certifications following an independent audit in Q1 2026. These are not self-attestations — they are third-party verifications that altovo meets the highest standards for information security and data management.

Certified

SOC 2 Type 2

Administered by the American Institute of Certified Public Accountants (AICPA).

SOC 2 Type 2 is the most rigorous version of the SOC 2 framework. Unlike Type 1 — which assesses controls at a single point in time — Type 2 evaluates whether security controls were actually operating effectively over an extended audit period. This means the auditor observed altovo's systems, processes, and controls in practice, not just on paper.

The audit covers the Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy. Achieving this certification demonstrates that altovo's controls were consistently applied throughout the observation period — not just when it mattered for a snapshot audit.

Governing body: AICPA
Audit completed: Q1 2026
Audit type: Independent third-party
Certified

ISO/IEC 27001:2022

The globally recognized standard for information security management systems (ISMS).

ISO/IEC 27001:2022 is the latest revision of the world's leading information security management standard. It establishes requirements for implementing, maintaining, and continuously improving an ISMS — a systematic approach to managing sensitive company and customer information so that it remains secure.

Certification requires an accredited external auditor to verify that altovo's security management system meets all 93 controls across four themes: Organizational, People, Physical, and Technological. The 2022 revision added new controls specifically addressing threat intelligence, cloud security, and information security for DevOps — all directly relevant to a SaaS travel platform.

Standard: ISO/IEC 27001:2022
Audit completed: Q1 2026
Audit type: Accredited external auditor
What it means for you

Why these certifications matter to your business.

For airlines, travel agencies, and enterprise clients, independent security certification provides something that self-attestation cannot: verified assurance.

Third-party verified

These certifications were awarded by independent auditors, not by altovo itself. That distinction matters enormously when your compliance team or enterprise procurement desk needs to approve a vendor.

Customer data protection

Traveller PII, payment credentials, and booking records flow through altovo's systems. Certification confirms that these are protected by controls that meet globally recognized standards — not just good intentions.

Vendor approval made easier

Airlines and enterprise travel buyers often require SOC 2 or ISO 27001 as a condition of contracting with technology vendors. altovo's certifications mean that requirement is already met — saving months of back-and-forth.

Continuous improvement

ISO 27001 is not a one-time badge — it requires annual surveillance audits and periodic recertification. This means altovo's security posture is continuously reviewed and improved, not frozen at the point of initial certification.

Systems, controls & data

The certifications cover altovo's systems, controls, and data management practices in full — not a limited scope subset. Every part of the platform that processes customer or partner data was included in the audit scope.

Sustained commitment

SOC 2 Type 2 assesses controls over an extended observation period, not a single moment. Certification demonstrates that altovo's security practices are consistent — not selectively applied only when auditors are watching.

"Security and compliance are foundational to everything we build. These certifications reflect the work the entire team has put in to meet the standards our partners expect."

Ron Ramanan — CEO, altovo
Announcement

altovo achieves dual security certification.

April 2026

altovo is pleased to announce that it has achieved both SOC 2 Type 2 and ISO/IEC 27001:2022 certifications following a comprehensive independent audit completed in Q1 2026. These certifications apply to altovo's full platform — covering the systems, controls, and data management practices that underpin every deployment we power.

The decision to pursue both frameworks simultaneously reflects the dual demands our enterprise clients face: US-headquartered airlines and corporate buyers typically require SOC 2; internationally regulated carriers and global enterprise accounts increasingly require ISO 27001. Holding both certifications means altovo meets the standard regardless of which framework a partner organization mandates.

These certifications are the result of sustained investment in our security programme — including dedicated security engineering, formal risk management processes, access control audits, incident response planning, and business continuity testing. The audit process confirmed that these controls were not only in place but operating effectively throughout the audit period.

For airlines, travel agencies, and enterprise clients who need to complete vendor security assessments before contracting with altovo, our certifications are available on request. Please contact your altovo account manager or reach out via the contact page.

Framework comparison

SOC 2 Type 2 vs. ISO/IEC 27001:2022 — what's the difference?

Many clients ask why altovo holds both certifications rather than choosing one. The answer is that they serve different purposes and are recognised differently across regions and buyer types.

SOC 2 Type 2
ISO/IEC 27001:2022
Governing body
AICPA (American Institute of Certified Public Accountants)
ISO/IEC — International Organization for Standardization
Primary region
United States and North America — widely required by US enterprise procurement teams
Global — recognized across Europe, Asia-Pacific, Middle East, and international markets
Audit approach
Observation over an extended period — tests whether controls operated consistently, not just whether they exist
Point-in-time certification with annual surveillance audits and triennial recertification
Scope
Trust Service Criteria: Security, Availability, Processing Integrity, Confidentiality, Privacy
93 controls across Organizational, People, Physical, and Technological themes
Best for
US airlines, US-headquartered corporate accounts, SaaS vendor reviews by US enterprise procurement
International airlines, EU-regulated entities, government-adjacent travel buyers, global enterprise accounts

altovo holds both — so whichever framework your procurement team requires, we already meet it.

Our security programme

Security is not a feature. It's the foundation.

The certifications are the output of a sustained, multi-year investment in security engineering, process, and culture across the entire altovo organisation.

Access control & identity

Least-privilege access is enforced across all altovo systems. Every employee and contractor has access only to the systems and data they need to do their job — and access is reviewed quarterly. Multi-factor authentication is mandatory for all staff accessing production environments. Privileged access is subject to additional controls and is fully logged.

Encryption in transit and at rest

All data transmitted between altovo's systems and client applications is encrypted using TLS 1.2 or higher. Sensitive data at rest — including PII, payment data references, and booking records — is encrypted using AES-256. Encryption key management is handled through a dedicated key management service with rotation policies enforced automatically.

Vulnerability management

Automated vulnerability scanning runs continuously across altovo's infrastructure and application code. Critical and high-severity findings are tracked to resolution within defined SLAs. Penetration testing is conducted annually by an independent third-party security firm. Findings and remediation timelines are reviewed at board level.

Incident response

altovo maintains a formal, tested incident response plan. The plan covers detection, containment, eradication, recovery, and post-incident review. Tabletop exercises are conducted twice annually. Client notification procedures are defined and practised — so if an incident ever occurs, affected parties are informed promptly and in accordance with regulatory requirements.

Business continuity & disaster recovery

Business continuity and disaster recovery plans are tested at least annually. Recovery time objectives (RTO) and recovery point objectives (RPO) are defined for all critical systems and reviewed as part of the ISO 27001 surveillance process. altovo's infrastructure is designed for high availability with redundant components across geographically separated zones.

Supplier & third-party risk

Every third-party supplier with access to altovo systems or data undergoes a security assessment before onboarding. Existing suppliers are reviewed annually. Contracts include mandatory security and data protection clauses aligned with our certification requirements. Cloud infrastructure suppliers — including AWS — are selected in part on the basis of their own independent certifications.

Common questions

Security FAQ

Can I request a copy of the audit report?

Yes. The SOC 2 Type 2 report is available to prospective and existing clients under NDA. The ISO/IEC 27001:2022 certificate is publicly available on request. Contact your account manager or use the contact page to request either document.

Does altovo handle payment card data?

altovo uses tokenisation and routes payments through PCI-DSS certified payment processors. Card numbers are never stored on altovo's systems. Payment data referenced within booking records uses secure tokens only — the underlying card data remains with the payment processor at all times.

Where is altovo's data hosted?

altovo's platform is hosted on AWS in enterprise-grade data centres. Data residency options can be discussed for clients with specific regulatory requirements around where their customer data is stored. Speak to our team for details specific to your jurisdiction.

How does altovo handle data breaches?

altovo's incident response plan includes defined timelines for client notification in the event of a security incident. Our obligations align with applicable data protection regulations. In addition to regulatory timelines, we aim to notify affected clients as rapidly as possible with clear information about what occurred and what steps we are taking.

Data protection

GDPR & data residency

altovo processes personal data in accordance with the GDPR and applicable data protection legislation in the jurisdictions where we operate. Data processing agreements (DPAs) are available to all clients and are a standard part of the altovo contracting process. For clients with specific data residency requirements — for example, where customer PII must not leave a particular country or region — speak to our team about available configuration options.

We maintain a full record of processing activities (ROPA) in line with GDPR Article 30 requirements. Our privacy programme is reviewed as part of the ISO 27001 surveillance cycle.

Sub-processors

Third-party sub-processing

altovo maintains an up-to-date list of sub-processors — third-party services that process personal data on our behalf. This includes cloud infrastructure providers, payment processors, and monitoring tools. The sub-processor list is available to clients on request and is updated whenever we add or remove a sub-processor. Clients are notified in advance of any changes that affect their data.

Every sub-processor is subject to due diligence before onboarding and annual review thereafter. Contracts with sub-processors include GDPR-compliant data processing terms and security obligations consistent with altovo's own certification requirements.

Questions about security?

We're happy to share our audit documentation.

If you need to complete a vendor security assessment or review altovo's certifications, get in touch with our team.

Contact us