Trust starts with
clear evidence.

Review the security and privacy foundations of the company behind WiseFin, and the data arrangements we address with each partner.

One operating company.
Four certified areas.

WiseFin is operated by Chengdu Weisifan Technology Co., Ltd., the company behind Zhibao Cloud. Its certifications cover information security, privacy management and personal information protection within the scopes below.

Certificate holder
Chengdu Weisifan Technology Co., Ltd.
Company registration
China · 91510100MA6B63GA2J
Records checked
12 September 2026

Certifications you
can review.

Read the original certificates and follow their verification links. All four linked records showed valid status on 12 September 2026.

01

ISO/IEC 27001:2022

Information security management

Information security management for the design, development and maintenance of insurance industry application software. Statement of Applicability: B/0.

Certificate number
04625I0367R101
Issuer
Beijing Head International Certification Co., Ltd.
Certificate expiry
02

ISO/IEC 27701:2019

Privacy information management

Privacy information management as a PII controller and processor for the design, development and maintenance of insurance industry application software. Statement of Applicability: B/0; based on the ISO/IEC 27001 certificate listed above.

Certificate number
04625PI0023R100
Issuer
Beijing Head International Certification Co., Ltd.
Certificate expiry
03

ISO/IEC 27018:2019

Public-cloud personal information protection

Personal information protection in public cloud related to Zhibao Cloud Platform SaaS services, excluding branches. Applicability Declaration: C/0.

Certificate number
87625CI1762R0S
Issuer
Data Network Information Authentication Service (Beijing) Co., Ltd.
Certificate expiry
04

ISO/IEC 29151:2017

Personally identifiable information protection

Personally identifiable information protection management related to Zhibao Cloud Platform SaaS services, excluding branches. Applicability Declaration: C/0.

Certificate number
87625PP1758R0S
Issuer
Data Network Information Authentication Service (Beijing) Co., Ltd.
Certificate expiry

Certificates apply to the named holder and stated activities. The 27018 and 29151 scopes exclude branches. Ongoing validity depends on the applicable audit requirements; the 27001 and 27701 issuer records specify the next audit before 12 November 2026. The 27701 certificate is based on the listed 27001 certification.

Compliance & Data

We work with partners to align data residency and processing arrangements with applicable local data protection requirements.

Data location

Agree the locations of production data, backups and recovery environments as part of the deployment design.

Access & responsibility

Define controller and processor responsibilities, permitted support access, user roles and data-processing terms.

Data lifecycle

Address retention, return and deletion arrangements, along with incident-response responsibilities and escalation.

Connected services

Review data flows to insurers, infrastructure providers and any AI or messaging services included in the project.

Working with partners in Kenya

For deployments in Kenya, we work with partners to align data residency and processing arrangements with Kenya’s Data Protection Act, 2019.

Read the ODPC’s data protection principles
Meet the Kenya team & review project arrangements

These certifications support supplier due diligence. They do not constitute local insurance regulatory approval, data-protection registration or confirmation of a particular hosting location. Requirements are assessed for the contracting entity and deployment.

Questions from
procurement teams.

Start with the evidence, then discuss the details of your proposed deployment.

Who holds the certifications?

All four listed certificates are held by Chengdu Weisifan Technology Co., Ltd.. WiseFin is its international-facing brand. The exact scope and certificate holder are shown above.

Can we review the original certificates?

Yes. Each record above includes the original English certificate PDF and its verification link. Our downloadable security and privacy brief brings the key information together.

Where will our insurance business data be hosted?

The production, backup and recovery locations are agreed for each project. The location of this marketing website does not determine where your insurance platform will be hosted.

How is support access addressed?

The proposed operating model should document who may access the environment, their permitted actions, approval and logging arrangements, and the responsibilities of the partner and WiseFin teams.

Does certification mean the deployment is locally approved?

Certification provides evidence of the stated management systems and activities. Local registration, insurance permissions, data flows and production approvals require a separate assessment for the project.

Let’s build your
next chapter.

Tell us where you want to take your insurance business. Let’s explore how the right technology can help.

Talk to our team