Skip to main content
    SectorsTechnology and software

    Some organizations are regulated by name. Others are regulated by their customers.

    If the product is software, or the business runs on it, the toolchain is not a back-office concern. It is the thing a buyer, an auditor or a named customer will ask you to answer for — and the questions arrive whether or not a regulator ever put you on a list.

    Two available today, one in beta Start a conversation Modern DevOps →

    We sit in the first line. We do not perform validation, independent review or effective challenge on our own work, and nothing we deliver is designed to stand in for your second or third line.

    Where the answer comes from already written
    the questionnaire right to audit · sub-processors · residency Assembled on request who has access what changed who approved and when a war room, and a slide Read from the record who changed it, who approved it written as the work happened answered Regulated by name, or by your customers. Same question. Whether the record satisfies a given buyer is their determination, not ours.
    The questions arrive whether or not a regulator named you. The only variable is whether the answer already exists.
    The pressure

    There may be no supervisor with your name on a list. There is always a customer who treats you as if there were.

    Nothing on this page depends on a regulator. It depends on the fact that your buyers have their own regulators, and the questions travel down the supply chain intact.

    01The toolchain is the product
    Source, CI, artifacts and the environments engineers work in are not adjacent to the business. They are how it ships.

    An estate nobody owns is not a tidiness problem. It is an operating risk, and it is one a buyer will find during diligence rather than one you will find first.

    AskCould you describe the estate to a customer who intends to test it?

    02Due diligence arrives as a questionnaire
    SOC 2 reports, ISO certificates, right-to-audit clauses and sub-processor lists land whether or not a regulator named you.

    The answers have to come from the record rather than from a slide assembled for the request. Assembly is the cost, it repeats, and it never appears on the plan.

    AskHow long did the last one take you?

    03Your buyers are inheriting obligations you will be asked about
    A regulated buyer under DORA now has named critical providers and a subcontracting standard to satisfy. You are in that chain.

    The European Supervisory Authorities designated the first nineteen critical ICT third-party providers in November 2025, and the subcontracting RTS reached the Official Journal in July 2025. Questions that used to stop at your customer now reach you.

    AskDo you know which of your customers are inside DORA?

    04Assistants are already in the path
    Engineers adopted them. The governance around them did not follow.

    A change proposed by a model is still a change, and somebody is still named as the person who accepted it. That name is the thing a questionnaire is eventually going to ask for.

    AskWhen a machine proposes a change, who accepts it?

    What buyers ask for

    The questions arrive without a supervisor.

    These are what software-dependent organizations are actually asked. We name them because they shape the work, and we claim nothing about your standing under any of them.

    What is measuredWhose figure, and whenWhy it is on this page
    SOC 2 Type II and ISO/IEC 27001 — the report and the certificate your customers ask for first, covering the design and operating effectiveness of controls over a period.Reign Ops holds SOC 2 Type II. Current attestation and certification status is provided on request under non-disclosure.Whether it satisfies a given buyer is their determination and not a claim we make here. Security and trust →
    ISO/IEC 42001:2023 — an AI management system: stated policy, defined roles, risk assessment, documented controls, continual improvement that produces records.Published 18 December 2023, unchanged. We hold no certification under it.Procurement teams at regulated buyers are starting to require it of software suppliers. Treat any global certification count you are shown with suspicion; the circulating figures do not trace to ISO or an accreditation body.
    Customer due diligence — right to audit, sub-processor lists, data-residency answers, and who can reach production.Continuous. No publication date, and no version to be current with.These are operating facts rather than documents. They should not take a project to assemble, and the fact that they usually do is the argument on this page.
    DORA, indirectly — your regulated customers now carry named critical-provider obligations and a subcontracting standard.Applying since 17 January 2025. First 19 critical providers designated 18 November 2025.You are unlikely to be designated. You are very likely to be asked, by a customer who was.

    Naming a framework is not a claim of standing under it. Beyond the SOC 2 Type II attestation stated above and on security and trust, iTmethods holds no certification, authorization or accreditation under any framework named on this page.

    Where the record fits

    We operate the estate and we record how the work was done.

    We do not certify you to your customers and we do not sit in your second line. Your teams keep the tools they chose; what changes is that the estate has an owner and the record exists before somebody asks for it.

    What the record carries
    What changed, who approved it and when, written as the work happens rather than reconstructed for a questionnaire. Where a model took part in producing a change, the identity that made the call, the policy that applied and the model that answered, joined to the change itself.
    The part worth being precise about. Whether that record satisfies a buyer, an auditor or a named customer is your call and theirs. Reign prepares; people decide. iTmethods makes no compliance, certification or accreditation claim under any framework. How the boundary works → · Regulatory alignment →
    The four motions

    Where this sits against the rest of Reign.

    Four motions at four different stages of maturity. We state the stage every time, because a buyer will ask which stage a thing is at, and the answer has to be the same every time.

    A single-tenant dedicated instance, in your own AWS or Azure account or in infrastructure iTmethods operates. Both are available today, which includes deployment into your own cloud account; Google Cloud is planned for 2027. Air-gapped and sovereign are in development. There is no multi-tenant or shared option at any tier. Deployment options →

    Shared responsibility

    Who holds what, when the questionnaire lands.

    Written down before anything is deployed, so the boundary is a document rather than a discovery during somebody else’s diligence.

    WhoWhat they hold
    iTmethodsOperate the delivery toolchain as a single-tenant dedicated instance, to your change control. Record what changed, who approved it and when. Keep the record readable without us.
    YouWhich tools your engineers use. Your code review, branch and release policy, unchanged. Every merge decision. What you tell a buyer, and whether the record answers what they asked.
    Nobody, everWe do not certify you to your customers, we do not sit in your second line, and we do not answer a questionnaire on your behalf. We supply the material the answer comes from.
    Before the scoping call

    The questions that arrive every time.

    Do you hold SOC 2?
    Reign Ops holds SOC 2 Type II. Current attestation and certification status, including scope and period, is provided on request under non-disclosure. Whether it satisfies a given buyer is their determination, and we do not make that claim on their behalf. Everything else we hold, and everything we do not, is on the product status register.
    Do you have ISO 42001?
    No. We describe it because regulated buyers are beginning to require it of their software suppliers, not because we hold it. If a buyer has told you they need it from you, that is a conversation about your management system rather than about our tooling.
    Will this help us answer a security questionnaire?
    It should make the answer shorter to produce, because the record already exists. It does not answer the questionnaire, it does not certify anything, and we will not sign an attestation on your behalf. The measure worth agreeing before we start is how long the last one took and what it cost you.
    What can you actually evidence today?
    The only figures we publish about this way of working are our own. Across eight of our own repositories, 326 merge requests were merged. Median time from merge request open to merge was 19 hours. 326 of 326 merged with a recorded approval from a named iTmethods engineer. Measured on our own engineering, 11 July to 11 August 2026, GitLab, release commits excluded, internal environment only, two-person team. The method is written up in full at what we measured. It is not a customer result, and we do not present it as one.
    Which deployment shapes can we have?
    A single-tenant dedicated instance, in your own AWS or Azure account or in infrastructure iTmethods operates. Both are available today, which includes deployment into your own cloud account; Google Cloud is planned for 2027. Air-gapped and sovereign are in development. There is no multi-tenant or shared option at any tier. Deployment options states which is which without softening any of them.
    AWS Advanced Tier Services Partner SOC 2 Type II on Reign Ops
    AWS Advanced Tier Services Partner and Validated Managed Service Provider. Twenty-one years operating regulated engineering environments.
    Next step

    Bring us the estate a buyer would ask about.

    We will tell you what we would take on, what we would leave alone, and what the record would look like at the end of it.