
Chronicle Is Now ISO/IEC 27001:2022 Certified
/ 3 min read
Chronicle has achieved certification to ISO/IEC 27001:2022, a globally recognized standard for information security management. Certification is awarded only after an organization's security controls are independently verified as comprehensive, documented, and continuously maintained. Chronicle’s certification was issued following an independent audit and covers the design, development, operation, and support of Chronicle's oracle services end to end. Specifically, the ISMS (Information Security Management System) includes our Proof of Asset, Data Feeds, and Dashboard products, alongside any supporting APIs, cloud environments, and other onchain and offchain infrastructure.
Chronicle is the longest-running oracle on Ethereum, with more than eight years of uptime without a hack or a security breach, supporting both crypto-native and institutional assets. Today Chronicle powers more than $13B across DeFi and tokenized assets, including BlackRock's BUIDL (tokenized by Securitize), Superstate's USTB, and the Janus Henderson Anemoy Treasury Fund (JTRSY) on Centrifuge, among others. This milestone formalizes and independently validates the infrastructure and controls that underpin all of these integrations.
What this means for our clients and partners
Funds, asset managers, capital allocators, and risk teams across financial institutions cannot adopt external infrastructure providers on reputation alone. As the industry matures, those moving into the digital asset space require independently issued assurance and third-party governance assessments rather than relying on a self-reported security posture. ISO/IEC 27001 supplies exactly that in the internationally recognized standard and form that financial institutions have used to evaluate all of their vendors for decades. For existing clients and partners, ISO certification adds independently audited evidence to a vendor relationship already in production and strengthens their own risk position. For prospective partners, the practical effect goes beyond the security assurance itself: Chronicle is now considerably easier and quicker to internally approve and integrate. Necessary security questionnaires, vendor-risk reviews and infosec sign-off — the steps that typically slow onboarding — can now resolve against an accredited ISMS instead of a bespoke, case-by-case assessment. That frees risk, compliance, and engineering teams to spend their time on the questions specific to their integration, rather than re-establishing baseline security facts an auditor has already verified.
The connection to Proof of Asset
Proof of Asset is a holistic data verification layer for tokenized assets. Rather than confirming that something backs a token, Proof of Asset surfaces exactly what backs it, at the holdings level, with cryptographic proof. The ISO-certified ISMS covers the full pipeline behind every Proof of Asset feed, from ingestion and validation through cryptographic signing and onchain publication. Proof of Asset already supports a growing range of tokenized financial products, each with different data requirements. For tokenized money market funds such as BlackRock's BUIDL, verification includes portfolio holdings, custody information, and token supply across chains. For private credit products such as ACRDX and structured credit funds such as the Janus Henderson Anemoy AAA CLO Fund, Proof of Asset shows complex portfolios, layered collateral, and changes in asset composition. With HYB issued via Centrifuge, Chronicle is extending that same holdings-level approach to an institutional U.S. corporate bond strategy.
"Institutions don't move onchain on faith. They move on verifiable assurance. The ISO/IEC 27001:2022 certification is independent confirmation that the way we design, operate, and secure our oracle infrastructure meets the standard the world's most rigorous financial institutions hold themselves to." — Niklas Kunkel, Chronicle Founder
Raising the standard for onchain finance
Chronicle's attainment of ISO/IEC 27001:2022 status is a reflection of the evolving requirements on data providers operating in an ecosystem that has become a fully connected financial market. Tokenized assets inherit the trustworthiness of the data and systems that report on them: without independently audited security controls underpinning them, tokenized assets don’t have the assurance institutions have come to expect and require. Chronicle has treated that as an engineering priority since deploying the first oracle on Ethereum in 2017. ISO/IEC 27001:2022 now makes this commitment legible to the institutions arriving onchain and sets the bar we expect the rest of the market to meet. Chronicle’s ISO/IEC 27001:2022 certification can be independently accessed via IAF CertSearch. To obtain a copy of the ISO 27001 certificate, reach out to Chronicle at hello@chroniclelabs.org.