Skip to content

Iru Earns ISO 27001 Certification

Iru Team Iru Team
Iru Earns ISO 27001 Certification

To earn the internationally recognized ISO 27001 certification, a company must demonstrate a commitment to implementing an information security management system (ISMS) followed by a rigorous two-stage audit. That’s why we’re so proud to announce that Iru has just received its own ISO 27001:2022 certification 

That certification—as well as our recent recertification in SOC 2—was achieved in part because we leverage Iru ourselves. 

To earn ISO 27001, a company must first implement an ISMS. Such systems encompass all the policies and procedures put in place to protect the security, availability, and confidentiality of an organization’s information assets. That system must first pass an internal audit, followed by that two-stage certification audit. The auditor then issues a certificate and registers the ISMS. Iru’s ISO certification can be verified by going to A-Lign and searching for certificate ISMS-KA-121123. 

The standard requires companies to demonstrate general capabilities, not to adopt specific tactics. 

So, for example, Annex 5.9 of the ISO spec requires you to demonstrate to the lead ISO auditor that you have some way of maintaining an inventory of information (and associated assets). Iru can help with that for Apple endpoints. Annex 7.14 requires organizations to have a system for securely disposing of old assets. Iru can safely erase Apple endpoints before they’re dispatched. Annex 8.7 of the ISO 27001 spec requires you to have some protection against malware. Iru’s own EDR product can do it, or you can use Iru to deploy and manage another solution. 

Iru can help you meet these and many other ISO 27001 requirements for Apple endpoints. Our  ISO 27001 certification can help provide reasonable assurance to Iru customers that Iru leverages a risk-based approach toward meeting its contractual commitments to protect customer data. This includes implementing policies and processes that are aligned with industry-accepted best practices.  

Our SOC2 recertification also underscores our commitment to the principles of security. It’s particularly significant because it represents our dedication to maintaining rigorous controls over a period of time rather than just at a single point.

The days when SaaS-based companies were eyed suspiciously by enterprise buyers because they didn’t conform to standards are long gone. Iru sailed through both of these compliance evaluations and did so using itself as an MDM. 

Our ISO 27001 certification and updated SOC2 report are available to current and prospective enterprise customers upon request through our trust portal, subject to the appropriate non-disclosure agreements. For more information about our security practices or these certifications, please visit that trust portal or email grc@iru.com.

About Iru

Iru is the Apple device management and security platform that empowers secure and productive global work. With Iru, Apple devices transform themselves into enterprise-ready endpoints, with all the right apps, settings, and security systems in place. Through advanced automation and thoughtful experiences, we’re bringing much-needed harmony to the way IT, InfoSec, and Apple device users work today and tomorrow.

Kandji is now Iru. This post was originally published under the Kandji brand. 

Recent Articles

Featured image: Remediating Windows vulnerabilities with a single tool
Matt Day 3 min read

Remediating Windows vulnerabilities with a single tool

Vulnerability Response is now available for Windows. Find, prioritize, and patch in one place, the same way you do for Mac.

Product News
Featured image: Rustbot, the macOS malware used in the latest Rust Supply Chain Attack
Cristian Molina 10 min read

Rustbot, the macOS malware used in the latest Rust Supply Chain Attack

On August 20, 2026, attackers published malicious versions of three widely used Rust packages to crates.io, the official Rust package registry. On macOS, the payload is a remote access trojan (RAT) that collects cloud credentials, SSH keys, cryptocurrency wallet data, and browser profile information, then sends it to attacker-controlled infrastructure. It installs a launch agent to survive reboots and accepts follow-on commands from its operators. Once running, it decrypts its configuration, profiles the host, Reads the local browser stores, installs persistence via LaunchAgent, and beacons out. The packages were available for approximately two hours before removal. The attackers also withdrew the previous stable versions, which pushed automated dependency resolution toward the compromised releases. Any environment that compiled an affected project during that window should be treated as compromised. This blog documents Iru's analysis of the native Apple Silicon ARM64 implant.

Threat Intelligence
Featured image: Inside the screensharingd Bugs: How macOS Screen Sharing Went from Root File Access to Pre-Auth Compromise
Csaba Fitzl 6 min read

Inside the screensharingd Bugs: How macOS Screen Sharing Went from Root File Access to Pre-Auth Compromise

In late July 2026, a cluster of vulnerabilities in macOS Screen Sharing turned what initially looked like a fairly constrained privilege problem into one of the more interesting macOS remote-attack stories in years.

Threat Intelligence

See Iru in action

Discover why thousands of teams choose Iru

By submitting this form I agree to Iru’s Privacy Policy and consent to be contacted by Iru about its products and services.

Stay up to date

Iru's bi-weekly collection of articles, videos, and research to keep IT & Security teams ahead of the curve.