ISO/IEC 27001:2022
Our information security management system is independently certified by MSECB. Certificate No. C1105-ISMS395-C2-04-24, valid through 2027-03-18.
Platform security
Incident and inspection reports often include photos, locations, and operational detail. Built by emAPPetizer Inc., 1st Reporting protects that data with encryption in transit, strong access controls, and clear privacy commitments—so IT and compliance teams can evaluate us with confidence.
Certification
MSECB has assessed and certified the management system of emAPPetizer Inc. in accordance with ISO/IEC 27001:2022.

The certification scope is limited to data belonging to emAPPetizer and its customers using their SaaS services, as well as employees’ personal data. This confidential data can be found on data centers, SharePoint, and backups residing in the infrastructure covered by the certification perimeter, in accordance with the Statement of Applicability (SoA), Ver. 1.6 dated 2024-03-04.
Subject to annual surveillance audits.
Our information security management system is independently certified by MSECB. Certificate No. C1105-ISMS395-C2-04-24, valid through 2027-03-18.
Communications with our services use encrypted channels (HTTPS/SSL). Payment details are encrypted before they are submitted through our payment providers.
Accounts require individual user credentials. Internally we use private-key server authentication, multi-factor authentication, and IP whitelisting to harden access to infrastructure.
Application hosting is provided by Microsoft in Canada. We document subprocessors—including payments, email, and support tooling—in our Privacy Policy.
emAPPetizer Inc. does not sell personal information to third parties. Data is used to operate the product, support customers, and improve the service as described in our Privacy Policy.
These practices are summarized from our published Privacy Policy so security reviewers have a clear starting point. For questionnaires, DPAs, or deeper architecture reviews, contact sales.
Users access 1st Reporting with individual logins and passwords. Optional sign-in with Microsoft 365, Google, or Apple is available where enabled for your organization.
Web servers are reachable over HTTPS and SSH. Server authentication uses private keys rather than passwords, with multi-factor authentication and internal IP whitelisting.
Card payments are processed by Stripe (or PayPal where used). Payment details are encrypted with SSL before submission; we do not store full card numbers on our application servers.
We retain account and service data while your account is active and as needed to provide the service or meet legal obligations. When you request deletion or close an account, data is removed from active systems; backup copies are erased on their scheduled lifecycle.
Depending on your jurisdiction, you may request access, correction, deletion, or other privacy rights. Contact privacy@emappetizer.com—we respond within thirty days.
If you use AI-powered features such as Template Genie, we process the inputs you provide to generate templates, suggestions, or summaries as described in the Privacy Policy.
Need a security questionnaire, vendor risk form, or data processing discussion for procurement? Our team works with IT and compliance stakeholders during evaluation. Share your requirements and we will respond with the documentation we can provide—including our ISO/IEC 27001:2022 certificate.
Subprocessors, cookies, international transfers, and user rights are documented in our Privacy Policy—the source of truth for how emAPPetizer Inc. handles personal information.
Start a trial to see the product, or talk with our team about security, compliance, and rollout for your field operations.
Yes. emAPPetizer Inc. holds an ISO/IEC 27001:2022 certificate issued by MSECB (Certificate No. C1105-ISMS395-C2-04-24), valid from 2024-04-18 through 2027-03-18, subject to annual surveillance audits. You can download the certificate from this page or request validation from MSECB at info@msecb.com.
Application hosting is provided by Microsoft in Canada. Other service providers (for example payments, email, and support) are listed in our Privacy Policy with their locations and privacy links.
No. We do not and will not sell personal information to third parties.
Communications with our services are encrypted in transit. Payment details are encrypted with SSL before submission to our payment gateway providers.
Yes. Contact sales with your questionnaire or vendor risk requirements and we will work through the review with your IT or compliance team.
For privacy requests, email privacy@emappetizer.com. For sales or vendor security reviews, use Contact Us or Book a Demo and mention security documentation.