TRUST & COMPLIANCE

Compliance & Security

ISO 27001:2022 certified, EU adequacy-aligned, and built on a cloud-first security architecture you can independently verify.

Security and compliance operations at Bogner & Partners
Certification ISO 27001:2022
Compliance Sprinto-Enforced
Data Protection EU GDPR-Aligned
Office Access Biometric
PRIMARY CERTIFICATION

ISO/IEC 27001:2022 Certified

Our Kenyan operating entity, Bogner Outsourcing Ltd, holds full ISO/IEC 27001:2022 certification covering the entire BPO service line. The certificate is independently auditable on the IAF (International Accreditation Forum) public database.

Certificate Details

Standard
ISO/IEC 27001:2022 (latest revision)
Certificate holder
Bogner Outsourcing Ltd
Westpark Towers, Mpesi Lane, Westlands, P.O. Box 5546, Nairobi, Kenya
Scope
Provision of Information Security Management System at Business Process Outsourcing (BPO) services, including Customer Service, Sales & Revenue Growth, Data Labeling, Finance, HR, and Back-Office operations.
Certificate number
JK1WNTSI20251226KENIS18M
Initial registration
26 December 2025
Validity
Through 25 December 2028
Surveillance audits
26 November 2026 · 26 November 2027
Issuing body
TNV System Certification Pvt. Ltd.
Accreditation
International Accreditation Services (IAS), MSCB 154 — recognized through the IAF Multilateral Recognition Arrangement
HOW WE OPERATE

Security Architecture

A cloud-first, zero-on-premise architecture with continuous compliance monitoring at the device level. Every claim below is part of our ISO 27001:2022 audit scope.

Sprinto Endpoint Compliance

The Sprinto agent runs on every employee device, enforcing disk encryption, automatic screen lock, and continuous compliance monitoring. Non-compliant devices are flagged and remediated automatically.

Cloud-First Architecture

No client data is stored on local servers. All client systems are accessed through TLS-encrypted connections, with role-based access controls enforced at the application level by each cloud platform.

Configurable VPN Access

VPN-based access between agents and client systems can be configured per client requirements, using enterprise solutions (Tailscale, Cisco AnyConnect, Cloudflare Access, or client-specified alternatives).

Biometric Office Entry

Our Nairobi office is secured by fingerprint-based entry control, generating an auditable record of physical access for ISO 27001 evidence.

Documented Clean Desk Policy

Per ISO/IEC 27001:2022 Annex A 7.7, all employees follow a documented clear-desk and clear-screen policy. Screen lock is enforced automatically by the Sprinto endpoint agent.

German Contract Framework

Clients can contract through Bogner & Partners (registered in Munich, HRB285639) under German commercial law, while operations run from our Nairobi entity.

DATA PROTECTION

GDPR-Aligned Data Handling

Kenya Data Protection Act (2019)

The Act is closely aligned with the EU's GDPR — covering data subject rights, controller/processor obligations, and extraterritorial scope. Kenya's legal system is based on English common law, providing familiar contractual frameworks for European businesses.

EU Adequacy Dialogue (May 2024)

In May 2024, Kenya and the European Commission launched the first formal Adequacy Dialogue with any African country. Kenya is in the final stages of becoming the first African country to receive an EU GDPR adequacy decision, which will allow personal data to flow freely from the EU to Kenya without additional transfer safeguards.

VERIFY OUR CREDENTIALS

Don't take our word for it

Every credential on this page can be independently verified through the issuing or accrediting body's public database.

Let's Build Your Team

Contact Us