What we have not certified
UVAMAI holds no ISO 27001 certification, no SOC 2 report, no PCI DSS attestation and no HIPAA assessment. We have not been independently audited against any security framework. We are stating this first because it is the thing a trust page is most often used to obscure.
We are not going to describe ourselves as "ISO-aligned", "SOC 2 ready" or "compliant with industry best practice". Those phrases mean nothing verifiable, and using them would tell you more about our marketing than our engineering.
If a certification is a hard requirement for your procurement process, say so early. We will tell you honestly whether we intend to pursue it and on what timescale, and if the answer does not work for you, we would rather you knew in the first conversation than the fifth.