-
ISO/IEC 27001 certification
-
Yes
-
ISO/IEC 27001 accredited by
-
Citation Limited
-
ISO/IEC 27001 accreditation date
-
Monday 4 March 2024
-
What the ISO/IEC 27001 doesn’t cover
-
Wellset Repro Limited’s (Flipside Group) ISO/IEC 27001 certification covers our core internal management systems, project delivery processes, and the secure handling of data within our corporate environment, the following areas fall outside our direct certification boundary:
Third-Party Infrastructure: We do not own or operate physical data centers. Our services are hosted on third-party Public Cloud platforms (e.g., AWS, Azure, Google Cloud). While we ensure these providers maintain their own ISO 27001 compliance, their physical security and hardware maintenance are outside our scope.
Buyer-Managed Systems: Security configurations, user access management, and software patches for systems owned or managed directly by the Buyer remain the Buyer’s responsibility unless specifically contracted as a managed service.
End-User Devices: The security of hardware or networks used by the Buyer’s staff to access our digital products is not covered.
Legacy Codebases: Security vulnerabilities inherent in pre-existing legacy code provided by the Buyer—which we have not developed or remediated—are excluded until brought under our development lifecycle.
-
ISO 28000:2022 certification
-
No
-
ISO 9001 certification
-
Yes
-
ISO 9001 certification accredited by
-
Citation Limited
-
ISO 9001 accreditation date
-
Thursday 27 November 2025
-
What the ISO 9001 doesn’t cover
-
Wellset Repro Limited’s (Flipside Group) ISO 9001 certification applies to our internal Quality Management System (QMS) and the delivery of digital consultancy, design, and software development services. However, the following areas are excluded from our certification scope as they are not applicable to our business model or are the responsibility of third parties:
Manufacturing and Physical Product Realization: As a digital service provider, we do not engage in the manufacture of physical goods or hardware. Requirements related to the control of physical production equipment and raw material logistics are excluded (Clause 8.5.1).
Post-Delivery Operational Ownership: While we provide structured handovers and support, our QMS does not cover the long-term operational management of live production environments unless specifically contracted as a managed service.
Third-Party Subcontractor Internal Quality: While we vet all partners and subcontractors to ensure they meet our quality standards, their own internal, non-project-related quality management systems are outside our direct certification boundary.
Hardware Maintenance: Maintenance and calibration of physical IT hardware (monitoring and measuring resources) used by the Buyer is excluded from our scope.
-
Quality management systems (QMS)
-
Yes
-
CSA STAR certification
-
No
-
PCI certification
-
No
-
Cyber essentials
-
Yes
-
Cyber Essentials Certificate Number
-
Ae06169d-67da-4109-ab36-9d9e8acb33ad
-
Cyber essentials plus
-
Yes
-
Cyber Essentials Plus Certificate Number
-
F33a4d85-1a2c-472f-8222-ba16a508e611
-
Other security certifications
-
No