Devolens Achieves ISO/ 27001:2022 Certification

Stockholm, Sweden | September 2, 2026

Devolens has achieved ISO/IEC 27001:2022 certification, strengthening the information security foundation behind its SaaS platform for software licensing.

The certification was issued to Cryptolens AB, the Swedish company behind Devolens, by Scandinavian Business Certification AB (SBcert). The certified management system covers the development and operation of SaaS services for software licensing.

ISO/ 27001 is an internationally recognized standard for information security management systems. Certification provides an independently audited framework for managing information security and maintaining processes for identifying, addressing, and continuously managing security risks.

For Devolens, the certification reflects the company's continued investment in the security, reliability, and operational foundation of the platform as it expands its capabilities and supports software companies with increasingly demanding requirements.

ISO 27001:2022 Certification

The certification applies to Cryptolens AB and covers the development and operation of SaaS services for software licensing.

Certification details:

  • Standard: ISO/IEC 27001:2022
  • Certificate holder: Cryptolens AB
  • Scope: Development and operation of SaaS services for software licensing
  • Certification body: Scandinavian Business Certification AB
  • Certificate number: SE559116-1749
  • Issued: August 31, 2026
  • Valid until: August 31, 2029

The certification follows an independent assessment of the information security management system against the requirements of ISO 27001:2022.

View the ISO 27001:2022 certificate

What ISO 27001 Means for Devolens

Devolens provides SaaS infrastructure that software companies use to manage licensing, subscriptions, entitlements, and access to their products. Information security is therefore an important part of operating the platform and supporting customers over the long term.

ISO 27001 provides a structured framework for managing information security across an organization. The certification reflects that Cryptolens AB has established and operates an information security management system that has been assessed against the requirements of the standard.

For customers and organizations evaluating Devolens, the certification provides an additional independently assessed reference point when reviewing the company's security and operational practices.

The certification complements Devolens's existing security documentation, data-processing terms, subprocessors information, and service availability information.

Review Devolens Security & Trust information

Devolens and Cryptolens AB

Devolens is a registered trademark and the SaaS platform operated by Cryptolens AB, a company based in Stockholm, Sweden.

The ISO 27001:2022 certificate is therefore issued to Cryptolens AB. Its certified scope covers the development and operation of SaaS services for software licensing, which includes the operations behind the Devolens platform.

This distinction ensures that customers and procurement teams can clearly connect the certification with the legal entity responsible for operating Devolens.

Building Devolens for the Long Term

The ISO 27001 certification is part of Devolens's continued investment in the platform and the organization behind it.

As Devolens expands from core licensing infrastructure into broader capabilities around licensing data, customer usage, and software business insights, maintaining a strong foundation for security and reliable operations remains an important part of that development.

The certification provides customers with an independently assessed reference point as they evaluate Devolens as a long-term software platform and technology partner.

For more information about Devolens's security practices, data processing, subprocessors, service availability, and ISO 27001 certification, visit the Security & Trust page.

Get Started with Devolens

Deploy licensing with a leading software licensing provider without long implementation cycles or added operational overhead.