AskCody holds an ISAE 3000 Type 2 declaration on the protection of personal data. The current ISAE 3000 report covers the period 1 June 2025 to 31 May 2026, was issued by BDO on 15 September 2026, and carries an unqualified opinion on both the design and the operating effectiveness of our controls. It is the document your security, privacy and procurement reviewers need in order to verify how AskCody processes personal data as a data processor under the GDPR and the Danish Data Protection Act.
What certification does AskCody hold?
AskCody is audited annually under ISAE 3000, Type 2, by BDO Statsautoriseret Revisionspartnerselskab, an independent state-authorised public accountant. The audit covers the AskCody Workplace Platform and AskCody's obligations as a data processor under the EU General Data Protection Regulation and the Danish Act on supplementary provisions.
Type 2 matters more than it sounds. A Type 1 opinion says the controls are suitably designed on a given date. A Type 2 opinion says the auditor also tested that they worked throughout the whole period, which is what a reviewer actually needs to see.
AskCody is not SOC 2 certified and not ISO 27001 certified. Our Information Security Policy is designed with reference to ISO 27001 principles and is aligned with the Volaris Group Digital Security Program, and the underlying Microsoft Azure platform carries its own ISO/IEC 27001, 27017, 27018 and SOC 2 Type 2 certifications. If a questionnaire asks for SOC 2, the honest answer is that the ISAE 3000 report is the assurance AskCody holds, and it is the equivalent evidence for GDPR processing.
What period does the current report cover?
The current report covers 1 June 2025 to 31 May 2026 and was signed by BDO on 15 September 2026. AskCody audits on a fixed 1 June to 31 May cycle, so the next declaration period runs from 1 June 2026 to 31 May 2027. When you request the report, you receive the most recent signed version, not a summary of it.
What is inside the ISAE 3000 report?
The report is a full description of the platform and the controls around it, tested control by control, with the auditor's result recorded for each one. It covers:
- the AskCody Workplace Platform and the processing activities carried out for controllers;
- the categories of personal data processed, the data subjects, and the purposes;
- the Information Security Policy, its eight chapters, and the annual approval and review;
- the risk assessment methodology and how it is maintained;
- access control, multi-factor authentication, encryption at rest and in transit, and logging;
- change management and secure development, including testing and segregation of duties;
- incident management and personal data breach procedures;
- the sub-processors in use during the period and the assurance relied on for each;
- deletion of personal data at the end of the provision of services.
The opinion on the current report is unqualified on all three limbs: fair presentation of the description, suitable design of the controls, and operating effectiveness throughout the period. The report also records two observations from the auditor. We do not hide them behind a summary: they are described in the report you receive, and we are happy to talk them through.
Has AskCody had a data breach?
No. The signed report states that there was no breach of the AskCody system, and no personal data breach, during the declaration period 1 June 2025 to 31 May 2026. Breach notification obligations are set out in our Data Processing Agreement, and the procedures behind them are part of what the auditor tests.
Why AskCody audits every year
As regulated in the Data Processing Agreement entered into with every client using the AskCody Platform, and as part of our promise to provide an enterprise-grade platform with the highest security standards implemented, AskCody performs a third-party audit and inspection every year to verify the compliance of data processing with respect to the Data Processing Agreement, the GDPR, our Information Security Policy, our Secure Development Policy, and all other security and compliance matters in AskCody.
The point of an independent auditor is that you do not have to take our word for it. A state-authorised public accountant has inspected and tested our security measures and our compliance, and documented that the measures exist and that they work. That is what lets our customers and business partners give their own users and employees a straight answer about how their personal data is handled.
On 1 October 2025 AskCody became part of Volaris Group, and the annual ISAE 3000 audit now sits alongside the continuous monitoring, enterprise tooling and shared governance of the Volaris Group Digital Security Program. The practical effect for a reviewer is that the annual report is no longer the only moment anything gets checked.
Understand how AskCody processes and protects data
The ISAE 3000 report is the assurance layer. The documentation underneath it is public. Our Help Center section on integrations and security covers how data is processed, stored, handled and managed, which data types, subject matters and categories are processed and for what purpose, which security requirements are implemented for each, and which sub-processors AskCody may use to deliver the platform and services.
It is worth reading next to the platform itself. AskCody runs natively on Microsoft 365 and Exchange, so meeting, room, visitor and service data stays inside the Microsoft tenant you already govern rather than being copied into a separate system with its own access model. That architecture is also why the reviewer question that usually takes longest, what happens to data once it leaves our tenant, has a short answer here.
Request the ISAE 3000 report
The report and the supporting documentation are provided on request, to customers and to organisations evaluating AskCody. Request the most recent Independent Auditor's ISAE 3000 report on the description of the AskCody Platform and the related technical and organisational measures for the processing and protection of personal data in accordance with the GDPR and the Danish act on supplementary provisions.
Current report: ISAE 3000 GDPR Type 2, declaration period 1 June 2025 to 31 May 2026, issued by BDO 15 September 2026. Page last updated 18 September 2026.

