This document is a technical report that outlines Borealis's security measures and certifications, specifically focusing on its compliance with ISO 27001:2017. It describes the security program design and implementation, which includes regular evaluations of information security risks and alignment with best practices. Key aspects covered in the report include confidentiality security, application-level security, organizational security processes, and security incident management. The document details the architecture of the Borealis application, emphasizing multi-tenant layers and strict access controls. It also discusses user monitoring, patch management, and vulnerability detection, along with data encryption methods and compliance measures. The report highlights the use of third-party security specialists and the deployment of enterprise-class security solutions for continuous infrastructure security. Additionally, it mentions the importance of a robust change management process integrated throughout the product lifecycle. Overall, the report provides a detailed overview of Borealis’s commitment to maintaining high standards of security and privacy.