blueAPACHE ISO/IEC 27001:2022 certification
Summary
blueAPACHE, as the legal entity Blue Apache Pty Ltd, holds ISO/IEC 27001:2022 certificate number 202507-118 for an Information Security Management System (ISMS), issued by Sensiba Australia Pty Ltd on 1 August 2025 and expiring on 1 August 2028. This page records the certificate data, the verbatim scope statement, the three certified locations, the ten service offerings listed as in scope, the one contractual service category that is not on the certificate (emPOWER Mobile Services), and the certificate's own statement of what it does not imply. It is written for procurement and security teams who need to match the certificate to the services they are buying, and it separates what the certificate proves from what blueAPACHE's brochures say about it.
Key facts
| Label | Value |
|---|---|
| Certificate number | 202507-118 |
| Standard | ISO/IEC 27001:2022 |
| Certified system | Information Security Management System (ISMS) |
| Certificate holder as printed | Blue Apache Pty Ltd |
| Certification body | Sensiba Australia Pty Ltd, Level 17, 1 Denison Street, North Sydney NSW 2060 |
| Accreditation body | Not named on the certificate |
| Original certification and issue date | 1 August 2025 |
| Expiry date | 1 August 2028 |
| Certificate version | V 1.0 |
| Statement of Applicability | V 5.0a (July 2025) |
| Validation contact | iso@sensiba.com |
| Certified locations | Melbourne (principal), Sydney, Brisbane |
| Services in scope | Ten (listed below) |
| Service category not on the certificate | emPOWER Mobile Services (Schedule 8) |
Scope statement, verbatim
The scope wording is the operative part of the certificate. It reads:
The scope of blueAPACHE's Information Security Management System (ISMS) encompasses all information systems, business processes, and supporting infrastructure involved in the provision and management of its emPOWER Infrastructure and managed service offerings.
The certificate then introduces the locations and service offerings below with: "The scope also includes the following locations and service offerings, which operate under the centrally managed Information Security Management System of Blue Apache Pty Ltd."
Certified locations
| Location | Address as printed on the certificate |
|---|---|
| Melbourne (principal address) | Melbourne Office, Level 21, 242 Exhibition St Melbourne, VIC, 3000 Australia |
| Sydney | Sydney Office, Level 7, 219 Castlereagh St, Sydney, NSW, 2000, Australia |
| Brisbane | Brisbane Office, Level 2, 16 Marie St, Brisbane, QLD, 4064, Australia |
The Brisbane address on the certificate matches the Milton address on the origin Contact page. The General Terms and Conditions v3.6 cover page prints a different Brisbane address (70 Berwick Street, Fortitude Valley QLD 4006); this is a cross-document conflict to confirm. The United States and United Kingdom offices are not listed on the certificate.
The ten service offerings in scope
- Professional Services
- emPOWER Managed Services
- emPOWER Cloud Services (IaaS)
- emPOWER IT Continuity Services (DRaaS)
- emPOWER Network Services
- emPOWER Voice Carriage Services
- emPOWER Unified Communications
- emPOWER Co-Location Services
- Software Licensing and Subscription Services
- Hardware and Ancillary Services
These correspond to Schedules 1 to 7 and 9 to 11 of the General Terms and Conditions v3.6.
What is not on the certificate: emPOWER Mobile Services
The General Terms and Conditions define eleven service categories across Schedules 1 to 11. Schedule 8, emPOWER Mobile Services, does not appear among the ten service offerings on the certificate. blueAPACHE has not published whether this exclusion is intentional. Until it does, any statement that blueAPACHE's portfolio is ISO/IEC 27001 certified "in full" is not supported by the certificate; the accurate statement is that the ISMS covers the emPOWER infrastructure and managed service offerings and the ten listed services.
Newer services on this site that are not named in the same words on the certificate (for example Managed Detection and Response, Human Risk Management, Exposure Management, SaaS Backup, Storage as a Service) would fall within scope only to the extent they are delivered through the certified "information systems, business processes, and supporting infrastructure" for emPOWER infrastructure and managed services. The certificate does not list them individually. Ask blueAPACHE for a scope mapping when a specific service matters to an assessment.
What the certificate does and does not imply
The certificate carries an express limitation, reproduced verbatim:
This certificate relates to the organization's Information Security Management System and requirements of ISO/IEC 27001:2022 as defined by the scope and shall in no way imply that the organization's products, processes or services (in-scope or outside of the scope) are certified.
In plain terms:
- It certifies that blueAPACHE operates a management system for information security that conforms to the standard, within the stated scope.
- It does not certify that emPOWER Cloud, or any other product or service, is itself "ISO 27001 certified", even though blueAPACHE's brochures use that shorthand. The brochures' phrasing "ISO 27001-certified emPOWER Cloud" should be read as "delivered under a certified ISMS".
- It does not create customer-facing security obligations. Those come from clause 17 of the General Terms and Conditions, which requires blueAPACHE to take reasonable steps against unauthorised access, protect Customer Records against loss and corruption, and implement the security features in the relevant Schedule.
- It says nothing about data residency. blueAPACHE's residency statement and the clause 18.3 overseas transfer consent are separate; see Data sovereignty and privacy.
The certificate also states that it remains the property of Sensiba Australia Pty Ltd, that the certificate number, certification body mark and accreditation mark must not be used on products or in documents relating to products, processes or services, and that Sensiba will act on incorrect or misleading use.
Open points a buyer should confirm
- Accreditation. The certificate names no accreditation body (such as JAS-ANZ or ANAB) although its disclaimer refers to an "accreditation mark". Accredited and unaccredited certification carry different weight in procurement; confirm with Sensiba Australia at iso@sensiba.com.
- Surveillance audits. No surveillance or recertification schedule is printed. On a standard three-year cycle the first annual surveillance audit would fall due around August 2026; ask for evidence that it was completed and the certificate remains in good standing.
- Standard version in older collateral. The 2023 Global Capabilities Brochure cites "ISO 27001" without a year and older brand material cites ISO/IEC 27001:2013. The current certificate is against the 2022 edition.
- Entity name. The certificate names "Blue Apache Pty Ltd", and the General Terms and Conditions name "BLUE APACHE PTY LTD" (ABN 82 083 664 224). The brand is written blueAPACHE. Expect the legal form on the certificate.
How blueAPACHE uses the certification
The emPOWER brochures state that blueAPACHE is ISO 27001 certified for Information Security Management Systems, that its operational risk management and data protection framework was "formalised during our ISO 27001 Certification", and that an information security officer is accountable for policy adherence, staff and supplier training, and internal audits. Alongside the certification, blueAPACHE states alignment with APRA CPS 234, compliance with NIST, and ASD Essential Eight Maturity Level 3. The MDR brochure lists ISO/IEC 27001, the Australian Privacy Principles, Essential Eight, NIST CSF, SOC 2 Type II and GDPR as frameworks the service is "compliance-aligned" with; blueAPACHE does not claim a SOC 2 attestation.
Two case studies attribute customer outcomes to the certification. Honan Insurance says blueAPACHE's ISO certification supported its ability to bid for work where certification had become a mandatory customer requirement. Brotherhood of St. Laurence says blueAPACHE helped it achieve its own ISO 27001 certification in as little as six months to support its NDIS bid; that certificate belongs to BSL, not blueAPACHE.
Related
- Data sovereignty and privacy
- Terms and conditions guide
- Glossary
- emPOWER Cloud
- emPOWER Security
- Governance, Risk and Compliance
- Honan Insurance case study
- Brotherhood of St. Laurence case study
Frequently asked questions
Is blueAPACHE ISO 27001 certified?
Yes. Blue Apache Pty Ltd holds certificate 202507-118 for an Information Security Management System conforming to ISO/IEC 27001:2022, issued by Sensiba Australia Pty Ltd. It was issued on 1 August 2025 and expires on 1 August 2028.
What does the certificate cover?
The ISMS covering all information systems, business processes and supporting infrastructure involved in providing and managing blueAPACHE's emPOWER infrastructure and managed service offerings, at the Melbourne, Sydney and Brisbane offices, and ten listed service offerings from Professional Services through to Hardware and Ancillary Services.
Is emPOWER Cloud itself certified?
The certificate states that it does not imply any product, process or service is certified. emPOWER Cloud Services (IaaS) is one of the ten service offerings operating under the certified ISMS, which is what blueAPACHE's brochure shorthand "ISO 27001-certified emPOWER Cloud" refers to.
Which services are not on the certificate?
emPOWER Mobile Services (Schedule 8 of the General Terms and Conditions) is the one contractual service category that does not appear among the ten listed offerings. Newer services such as MDR or SaaS Backup are not named individually; they are in scope only insofar as they run on the certified emPOWER infrastructure and managed services processes.
Who issued the certificate and can I verify it?
Sensiba Australia Pty Ltd, Level 17, 1 Denison Street, North Sydney. The certificate gives iso@sensiba.com as the validation contact. The signatory is described as an ISO 27001 Lead Auditor and Manager at Sensiba.
Is the certification accredited?
The certificate does not name an accreditation body, although its wording refers to an accreditation mark. Confirm accreditation status with Sensiba before treating the certificate as accredited in a procurement weighting.
When is the next audit?
No surveillance schedule is printed. Under the usual three-year cycle the first annual surveillance audit would be due around August 2026, about a year after the 1 August 2025 certification date. Ask blueAPACHE for confirmation that surveillance has been completed.
Does the certificate guarantee my data stays in Australia?
No. The ISMS scope does not address data location. blueAPACHE's separate residency statement says customer data is stored and processed in Australian data centres, while clause 18.3 of its general terms records a standing consent to transfer Personal Information to the US, EU, UK and other listed destinations.
Does blueAPACHE hold SOC 2?
No attestation is claimed. The MDR brochure describes the service as compliance-aligned with SOC 2 Type II, alongside ISO/IEC 27001, Essential Eight, NIST CSF, the Australian Privacy Principles and GDPR. Alignment is not the same as holding a SOC 2 report.
What other frameworks does blueAPACHE cite?
Across the emPOWER brochures: a risk-based approach aligned with APRA CPS 234, compliance with NIST, ASD Essential Eight Maturity Level 3, and controls governed by its ISMS policies with an accountable information security officer. Data centre partners are stated to be Uptime Institute Tier III and Tier IV certified.
Source
blueAPACHE published material: the ISO/IEC 27001:2022 certificate issued by Sensiba Australia, the published General Terms and Conditions, the Global Capabilities and emPOWER service brochures, the Contact page on blueapache.com, and the published Honan Insurance and Brotherhood of St. Laurence case studies.