Salta al contenuto principale

Choosing software

Vendor certifications and audits for condominium software

Among the questions to put to a condominium software vendor is the one about certifications: which independent attestations the organization holds to guarantee its management of security. A serious certification is not a logo to display, but the result of an external check that verifies the existence of documented processes. Knowing which certifications the vendor holds, and above all what they attest, helps the manager assess the solidity of the platform to which they entrust the data of dozens of families. This guide explains what to ask and how to interpret the answer without being dazzled by acronyms.

What to check about certifications

  1. Which certifications does the vendor hold and over what scope?
  2. Do the certifications cover the very service offered to the condominium?
  3. Are they currently valid and periodically renewed?
  4. Are they issued by an independent, accredited body?
  5. Can the vendor provide evidence of the certificate or a summary?

What a certification actually attests

The most cited certification in the world of information security is ISO 27001, which covers the security management system. It does not certify that the software is impregnable, but that the organization has adopted and maintains documented processes to identify risks, define measures, and improve over time. It is a guarantee of method, not a promise of infallibility.

This distinction matters. A certified vendor has demonstrated to an external auditor that it has procedures to manage access, incidents, backups, and staff training. A vendor without certifications can still be serious, but the manager must assess its security with other tools, without the comfort of an independent check.

Pay attention to the scope

A certification always has a scope, meaning a precise area to which it applies. A company may be certified for part of its activities but not for the service actually used by the condominium. That is why it is not enough to know that the vendor holds a certification: you must verify that it covers the very platform and processes that handle the condominium's data.

Ask therefore to see the certificate or a summary indicating the scope. A transparent answer specifies the scope and the validity. An evasive answer, which merely cites an acronym with no documentation, does not let you understand whether the certification is really relevant to the service you are evaluating.

  • Verify that the scope includes the service used by the condominium.
  • Check the validity date and the renewal frequency.
  • Confirm that the certifying body is independent and recognized.
  • Ask for documentary evidence, not just the mention of the acronym.

Beyond certifications: security assessments

Certifications are not the only signal. Many serious vendors periodically subject their infrastructure to security assessments carried out by external parties, such as vulnerability tests. It is not necessary to obtain the detailed reports, which are confidential, but it is reasonable to ask whether these assessments exist and how often they are performed.

Even without a formal certification, a vendor that documents its security measures, trains its staff, and tests its recoveries offers concrete guarantees. The manager's goal is not to collect logos, but to understand whether behind the service there is a real and continuous security oversight.

How to weigh certifications in the choice

A recognized certification is a positive element, but it must be placed in the overall picture together with data location, the processing agreement, backup policies, and transparency about the supply chain. A certified vendor that does not provide the processing agreement remains an incomplete vendor. The security questions must be read together, not in isolation.

AmministraPro adopts documented security measures to protect condominium data and makes its choices transparent in the contractual documentation. You can explore the platform's setup on the /funzioni page and compare the plans on /prezzi before deciding.

Frequently asked questions

Does ISO 27001 guarantee that the software is secure?

Not exactly. ISO 27001 certifies that the organization has adopted a documented information security management system, with processes to assess risks and adopt measures. It does not attest to the software's impregnability, but to the presence of a method verified by an independent body.

Should a vendor without certifications be ruled out?

Not necessarily. A certification is a useful signal but not the only one. A vendor without certification can be reliable if it documents its security measures, provides the processing agreement, and is transparent about the data. In that case the manager assesses security using other elements.

What is the scope of a certification?

It is the precise area to which the certification applies. A company may be certified for part of its activities but not for the service actually used by the condominium. Always verify that the scope includes the platform and the processes that handle the condominium's data.

Can I ask for the security test reports?

Detailed vulnerability test reports are generally confidential, because they contain sensitive information about the infrastructure. It is however reasonable to ask whether the vendor carries out external assessments periodically and how often, possibly obtaining a summary of the outcome.

Try AmministraPro

Accounting, thousandths-based cost splitting, meetings, communications and artificial intelligence in a single Italian software, compliant with UNI 10801 and GDPR.