Undermapsยท Trust Centre
All systems operational

Undermaps
Trust Centre

Undermaps is a cloud-based platform for subsurface infrastructure mapping and utility location powered by Reveal. Security is built into how we operate, our Information Security Management System is ISO/IEC 27001:2022 certified, and we run regular independent audit, penetration testing, continuous vulnerability monitoring, and least-privilege access controls across our infrastructure.

Certifications

Independently audited

Click any certification to see scope, auditor and how to access the underlying report.

ISO27001 POWERED BY SWISE

ISO 27001

Issued by BSI ยท Valid through 15 Jan 2029

This certification confirms that Reveal's Information Security Management System covering the design, development, and support of the Undermaps platform meets the requirements of ISO/IEC 27001:2022. It reflects independent, third-party verification of the security controls protecting Undermaps and its customers

AuditorBSILast audit12 Dec 2025Valid until15 Jan 2029ScopeCovers all people, process, technology, infrastructure, and facilities used in the design, development, implementation, and support of Reveal's software applications Undermaps as well as utility location, data collection, and processing services. Certified entities: Reveal Infrastructure Limited, Reveal Technology Limited, Reveal Australia Pty Ltd, and Reveal USA, Inc.
Attachments

Controls

4 Context of the organization (Mandatory Clause)

  • โœ“4.2 Understanding the needs and expectations of interested parties
  • โœ“4.4 Information security management system
  • โœ“4.1 Understanding the organization and its context
  • โœ“4.3 Determining the scope of the information security management system

7 Support (Mandatory Clause)

  • โœ“7.5.2 Creating and updating - Documented information
  • โœ“7.1 Resources
  • โœ“7.5.3 Control of documented information - Documented information
  • โœ“7.2 Competence
  • โœ“7.5.1 General - Documented information
  • โœ“7.4 Communication
  • โœ“7.3 Awareness
View 2 more 7 Support (Mandatory Clause) controls

5 Leadership (Mandatory Clause)

  • โœ“5.3 Organizational roles, responsibilities and authorities
  • โœ“5.1 Leadership and commitment
  • โœ“5.2 Policy

8 Operation (Mandatory Clause)

  • โœ“8.3 Information security risk treatment
  • โœ“8.1 Operational planning and control
  • โœ“8.2 Information security risk assessment

10 Improvement (Mandatory Clause)

  • โœ“10.1 Continual improvement
  • โœ“10.2 Nonconformity and corrective action

9 Performance evaluation (Mandatory Clause)

  • โœ“9.3.1 General - Management review
  • โœ“9.2.1 General -Internal audit
  • โœ“9.3.2 Management review inputs - Management review
  • โœ“9.3.3 Management review results - Management review
  • โœ“9.1 Monitoring, measurement, analysis and evaluation
  • โœ“9.2.2 Internal audit programme - Internal audit
View 1 more 9 Performance evaluation (Mandatory Clause) controls

8 Technological controls (Sec Control)

  • โœ“8.31 Separation of development, test and production environments (Sec Control)
  • โœ“8.29 Security testing in development and acceptance (Sec Control)
  • โœ“8.6 Capacity management (Sec Control)
  • โœ“8.20 Networks security (Sec Control)
  • โœ“8.19 Installation of software on operational systems (Sec Control)
  • โœ“8.11 Data masking (Sec Control)
  • โœ“8.22 Segregation of networks (Sec Control)
  • โœ“8.14 Redundancy of information processing facilities (Sec Control)
  • โœ“8.34 Protection of information systems during audit testing (Sec Control)
  • โœ“8.32 Change management (Sec Control)
  • โœ“8.5 Secure authentication (Sec Control)
  • โœ“8.21 Security of network services (Sec Control)
  • โœ“8.30 Outsourced development (Sec Control)
  • โœ“8.9 Configuration management (Sec Control)
  • โœ“8.7 Protection against malware (Sec Control)
  • โœ“8.28 Secure coding (Sec Control)
  • โœ“8.23 Web filtering (Sec Control)
  • โœ“8.26 Application security requirements (Sec Control)
  • โœ“8.8 Management of technical vulnerabilities (Sec Control)
  • โœ“8.4 Access to source code (Sec Control)
  • โœ“8.17 Clock synchronization (Sec Control)
  • โœ“8.27 Secure system architecture and engineering principles (Sec Control)
  • โœ“8.16 Monitoring activities (Sec Control)
  • โœ“8.25 Secure development life cycle (Sec Control)
  • โœ“8.18 Use of privileged utility programs (Sec Control)
  • โœ“8.33 Test information (Sec Control)
  • โœ“8.12 Data leakage prevention (Sec Control)
  • โœ“8.3 Information access restriction (Sec Control)
  • โœ“8.15 Logging (Sec Control)
  • โœ“8.10 Information deletion (Sec Control)
  • โœ“8.1 User end point devices (Sec Control)
  • โœ“8.13 Information backup (Sec Control)
  • โœ“8.24 Use of cryptography (Sec Control)
  • โœ“8.2 Privileged access rights (Sec Control)
View 29 more 8 Technological controls (Sec Control) controls

5 Organizational Controls (Sec Control)

  • โœ“5.29 Information security during disruption (Sec Control)
  • โœ“5.34 Privacy and protection of personal identifiable information (PII) (Sec Control)
  • โœ“5.3 Segregation of duties (Sec Control)
  • โœ“5.37 Documented operating procedures (Sec Control)
  • โœ“5.21 Managing information security in the ICT supply chain (Sec Control)
  • โœ“5.8 Information security in project management (Sec Control)
  • โœ“5.13 Labelling of information (Sec Control)
  • โœ“5.4 Management responsibilities (Sec Control)
  • โœ“5.26 Response to information security incidents (Sec Control)
  • โœ“5.18 Access rights (Sec Control)
  • โœ“5.11 Return of assets (Sec Control)
  • โœ“5.32 Intellectual property rights (Sec Control)
  • โœ“5.5 Contact with authorities (Sec Control)
  • โœ“5.9 Inventory of information and other associated assets (Sec Control)
  • โœ“5.19 Information security in supplier relationships (Sec Control)
  • โœ“5.10 Acceptable use of information and other associated assets (Sec Control)
  • โœ“5.6 Contact with special interest groups (Sec Control)
  • โœ“5.2 Information security roles and responsibilities (Sec Control)
  • โœ“5.36 Compliance with policies, rules and standards for information security (Sec Control)
  • โœ“5.33 Protection of records (Sec Control)
  • โœ“5.14 Information transfer (Sec Control)
  • โœ“5.23 Information security for use of cloud services (Sec Control)
  • โœ“5.16 Identity management (Sec Control)
  • โœ“5.22 Monitoring, review and change management of supplier services (Sec Control)
  • โœ“5.25 Assessment and decision on information security events (Sec Control)
  • โœ“5.12 Classification of information (Sec Control)
  • โœ“5.15 Access control (Sec Control)
  • โœ“5.24 Information security incident management planning and preparation (Sec Control)
  • โœ“5.30 ICT readiness for business continuity (Sec Control)
  • โœ“5.7 Threat intelligence (Sec Control)
  • โœ“5.31 Legal, statutory, regulatory and contractual requirements (Sec Control)
  • โœ“5.27 Learning from information security incidents (Sec Control)
  • โœ“5.28 Collection of evidence (Sec Control)
  • โœ“5.35 Independent review of information security (Sec Control)
  • โœ“5.17 Authentication information (Sec Control)
  • โœ“5.1 Policies for information security - (Sec Control)
  • โœ“5.20 Addressing information security within supplier agreements (Sec Control)
View 32 more 5 Organizational Controls (Sec Control) controls

7 Physical Controls (Sec Control)

  • โœ“7.4 Physical security monitoring (Sec Control)
  • โœ“7.7 Clear desk and clear screen (Sec Control)
  • โœ“7.3 Securing offices, rooms and facilities (Sec Control)
  • โœ“7.13 Equipment maintenance (Sec Control)
  • โœ“7.2 Physical entry (Sec Control)
  • โœ“7.1 Physical security perimeters (Sec Control)
  • โœ“7.14 Secure disposal or re-use of equipment (Sec Control)
  • โœ“7.10 Storage media (Sec Control)
  • โœ“7.12 Cabling security (Sec Control)
  • โœ“7.6 Working in secure areas (Sec Control)
  • โœ“7.8 Equipment siting and protection (Sec Control)
  • โœ“7.9 Security of assets off-premises (Sec Control)
  • โœ“7.11 Supporting utilities (Sec Control)
  • โœ“7.5 Protecting against physical and environmental threats (Sec Control)
View 9 more 7 Physical Controls (Sec Control) controls

6 People Controls (Sec Control)

  • โœ“6.2 Terms and conditions of employment (Sec Control)
  • โœ“6.3 Information security awareness, education and training (Sec Control)
  • โœ“6.6 Confidentiality or non-disclosure agreements (Sec Control)
  • โœ“6.1 Screening (Sec Control)
  • โœ“6.5 Responsibilities after termination or change of employment (Sec Control)
  • โœ“6.4 Disciplinary process (Sec Control)
  • โœ“6.7 Remote working (Sec Control)
  • โœ“6.8 Information security event reporting (Sec Control)
View 3 more 6 People Controls (Sec Control) controls

6 Planning (Mandatory Clause)

  • โœ“6.1.1 General - Actions to address risks and opportunities
  • โœ“6.3 Planning of changes
  • โœ“6.1.2 Information security risk assessment: Actions to address risks and opportunities
  • โœ“6.2 Information security objectives and planning to achieve them
  • โœ“6.1.3 Information security risk treatment: Actions to address risks and opportunities
Compliance scope

Which products are covered?

Here you'll find which certifications apply to each Undermaps product. Cells marked N/A are out of scope; In progress means an audit is currently underway.
ProductISO 27001
Undermapsโœ“
FAQ

Common questions

Answers to the questions we receive most often during security reviews.

What is Undermaps?โ–พ
Undermaps is a cloud-based platform for managing, visualising, and sharing underground utility and infrastructure data, hosted on Microsoft Azure with enterprise-grade security controls.
Where is my data hosted?โ–พ
Undermaps is hosted within Microsoft Azure Australia East. Customer data is stored and processed within Australia unless otherwise contractually agreed, and is not stored offshore.
Is Undermaps ISO 27001 certified?โ–พ
Yes. Reveal, the team behind Undermaps, is certified to ISO/IEC 27001:2022 through BSI.
Do you perform penetration testing?โ–พ
Yes. Undermaps undergoes annual independent penetration testing alongside continuous vulnerability scanning and infrastructure security reviews.
How is my data encrypted?โ–พ
ata is encrypted at rest using AES-256 and in transit using TLS 1.3. HTTPS is enforced across all services and APIs.
How are encryption keys managed?โ–พ
Encryption keys are securely managed with controlled access, automated rotation, and secure certificate management.
How is my data kept separate from other customers?โ–พ
Undermaps uses logical tenant segregation, organisation-specific access boundaries and role-based permissions ensure users can only access data for organisations they're authorised for.
Do you support MFA and SSO?โ–พ
Yes. SSO integration is supported using enterprise identity providers, through which multi-factor authentication (MFA) is available.
What happens if there's a security incident?โ–พ
Reveal maintains a formal Security Incident Response Plan covering detection, severity classification, containment, recovery, and customer communication. The plan is tested annually.
What are your backup and disaster recovery capabilities?โ–พ
Backups are encrypted and isolated from production systems. Reveal maintains disaster recovery processes including backup restoration testing and annual DR exercises.
How do you manage vulnerabilities and patching?โ–พ
Vulnerabilities are identified through continuous scanning and third-party penetration testing, with formal remediation tracking and defined patching SLAs. Critical vulnerabilities are prioritised for immediate remediation.
Can I export my data, and what happens when my contract ends?โ–พ
Yes, data can be exported on request in the format it was provided. On contract end, data is securely deleted in line with contractual and retention obligations.
Do you use AI, and is my data used to train AI models?โ–พ
Reveal uses approved AI tools under a formal Responsible Use of AI Policy, limited to internal productivity and development support. Customer data is never used to train external AI models.
Can I request additional security documentation?โ–พ
Yes. Additional documentation including policy summaries, penetration testing summaries, and compliance certificates may be available under NDA. Contact support@undermaps.com

Request access