Certificates and approvals
And will this stand up to an audit?
We are not asking you to take our word for it. Every one of these papers means that somebody from outside came, looked at how we work and signed to say it is right. We are not going to tell you here what the standard says: we are going to tell you what it saves you.
What a certificate is actually for.
It is not an ornament for the website. It is the box you will be asked to tick in the tender specification, in the purchasing committee and in whatever audit turns up afterwards — and it is the difference between your file going through or sitting there while somebody justifies why a supplier without it was hired.
That is why they are set out company by company and not in one common list. The installer company certificate belongs to WestPoint, because WestPoint is the one that installs. The Centro Español de Metrología approval belongs to Neural Pax, which is an Infinity product. Lumping them together would suggest everyone holds everything, and that is not the case.
And every one of them can be requested. The exact scope and the expiry date are on the document issued by the auditing body, not on this page. Ask us and we will send them: checking is a right of yours, not a favour from us.
WestPoint. Installer company no. 3709.
Ministry of the Interior. It is the one that decides whether we may touch your security installation or not.
What it is.
The legal authorisation to design, equip, install and maintain electronic security systems: alarms, closed-circuit television, access control. In Spain it is not optional and it is not a quality mark — it is the requirement for being allowed to do the work at all.
What you get.
That your security installation is done by someone who is allowed to do it. It sounds obvious and it is not: part of the market is fitted by companies that are not registered, and the day there is an incident and the insurer or the inspector asks for the installer's certificate, that paper does not exist and the problem becomes yours.
The number is 3709 and it can be checked. You do not have to believe us: it is in the Ministry register.
WestPoint. RASIC registration.
Ministry of Industry. Technical and financial standing, accredited by somebody who is not us.
What it is.
The Ministry of Industry's register of installer companies. Getting in means proving three things: that there are genuinely competent staff, that there are the means to carry out and maintain what is installed, and that the company can financially sustain the work it signs for.
What you get.
In a tender, the technical standing box arrives already evidenced and does not have to be built up out of works certificates and sworn declarations. And on a long project, it means the company signing a five-year maintenance contract has something to sustain it with: a security system whose installer disappears in the second year becomes your problem, not theirs.
Infinity Neural. CEM approval.
Centro Español de Metrología, the Spanish national metrology institute. The accuracy of the counting is not something we claim: it is measured by a third party.
What it is.
The Centro Español de Metrología is the body that says whether an instrument measures properly: the same one that approves a weighing scale or a speed camera. It approved Neural Pax for counting people autonomously and automatically, and that means it measured how far off it goes and under what conditions, and put it in writing with its stamp.
Watch the scope, because that is usually where the catch is: what is approved is that measurement —people counting done the way the protocol requires, with the camera where it should be and with the field of view it demands— and not the whole product or any old installation. Mounted another way it counts just as well or just as badly, but it is no longer approved.
What you get.
That when you say twelve thousand people came in yesterday, that number is backed by somebody from outside. It is not an estimate from your system: it is a verified measurement.
And that difference shows in exactly four places, which are the ones where the problem turns up: justifying an occupancy figure to an inspection, negotiating a rent calculated on footfall, charging an advertiser for impressions, and comparing this month's figure with last year's knowing it was counted the same way. In those four, an estimate does not hold up.
Upon Group. The four usual ISOs.
Quality, environment, workplace safety and information. They belong to the whole group, not to one company.
ISO 9001 · How we work.
It requires the way of working to be written down, measured to see whether it works, and corrected when it does not. What you get: if something goes wrong there is a procedure to put it right and to stop it happening again, and it does not depend on the technician who knows the trick being on duty that day. In many public tenders it appears as a technical standing requirement.
ISO 27001 · Information security.
Somebody from outside reviews who can get into what, how the keys are kept and how anyone notices that something is wrong. What you get: your IT department asks for the certificate and checks it, instead of sending us a forty-page questionnaire and then having to assess it. In a system that handles images of people, this is the one that closes the most questions.
ISO 45001 · The safety of the people doing the work.
This one is about the people who install and maintain: whoever climbs an eight-metre column to fit a camera, or goes into a water treatment plant or a tunnel. What you get: the people who set foot on your site arrive trained, with equipment and with a procedure, which is exactly what you will be asked to evidence in the coordination of business activities. If there is an accident on your premises, the documentation exists.
ISO 14001 · Environmental impact.
It measures and reduces what gets used and what gets thrown away: equipment consumption, electronic waste, life cycle. What you get: in a public tender the environmental criteria score points, and a certified supplier adds instead of subtracting. And if your organisation has to account for its sustainability targets, those numbers are already measured and audited and you do not have to estimate them yourself.
Upon Group. The three ISO standards that are not the usual ones.
Artificial intelligence, privacy and continuity. These are the new ones, and they are the ones asked about by the committees that have already had a fright.
ISO/IEC 42001 · Artificial intelligence under control.
It is the newest of the lot and it is about exactly this: how an artificial intelligence system is built and watched so that it does not end up doing odd things without anyone noticing. What you get: the written answer to the most uncomfortable question in a purchasing committee, which is «and the artificial intelligence — who controls that?». It is documented who trains the models that look at your cameras, with what data, who checks that they get it right and what happens when they get it wrong.
ISO/IEC 27701 · People's privacy.
It is the sister of 27001 but centred on people's data: what is kept about somebody, what for, for how long and who can see it. What you get: the day somebody asks what is kept about them, there is a written procedure and not an improvisation. And when the time comes to justify the handling of images to the data protection authority or to your own data protection officer, the work is already done and audited.
ISO 22301 · Keeping it running.
It is about what happens on the bad day: a fire, a cyber attack, a flood in the server room. The standard makes you write it down and, above all, have tested it. What you get: when a tender asks what happens the day the system goes down and how long it takes to come back, that answer is measured and rehearsed, not estimated by somebody in sales.
The national and European framework.
The two that decide whether you can hire us without opening a file to justify it.
ENS High level.
The Esquema Nacional de Seguridad (ENS, the mandatory security framework for the systems used by the Spanish public administration) has three levels, and high is the most demanding: the one for systems whose failure would have serious consequences. What you get: if you are a public authority, you can hire us without opening a file to justify why, and that shows in how long it takes to go through. For public administration systems the ENS is not optional: either the supplier has it, or the file stops.
NIS2.
It is the European directive that requires the sectors daily life depends on —energy, water, transport, healthcare— to protect themselves against cyber attacks. It distinguishes between essential and important entities according to sector and size. What you get: if your organisation is bound by NIS2, your suppliers come into the equation, because the directive looks at the whole supply chain and not only at your own house. With us that box is already ticked.
The certificate is not the guarantee. The method is.
And it is worth separating the two, because half the industry sells the first as if it were the second.
A certificate says there is a procedure that is written down, measured and audited by somebody from outside, and that if something fails you can reconstruct what happened. That is a lot: it is the floor. What it does not say is that your installation will turn out well, because that does not depend on the paper — it depends on what is done on your site, on your visit and in your maintenance.
That we do guarantee, and you can check it because it is always the same.
The method.
- We look before we say anything. Camera by camera, on site, in the light there is at that hour. No proposal comes out of a drawing and a catalogue: it comes out of having been there.
- What cannot be done is said at the site visit. Not at commissioning, not on the day of the incident. If a camera is not up to what you want, the answer is to move the column, and you are going to hear it before you sign.
- It starts small. A few cameras and one or two rules, checking that it detects what is expected before it grows. Nobody has to take anything on trust up front.
- What is handed over is tested. The alarms are set off on purpose to see whether they arrive, and who they arrive to. A system that has never been tested is not handed over, it is installed.
- It is documented so that it works without us. Drawings, configuration, who receives what and why. If you change supplier tomorrow, you take away a system that can be understood.
- And we come back. Maintenance is a visit with a date on it, not a phone number to call when something breaks. That is what decides whether this is any use three years from now.
And what we are not going to call certification.
Being certified by a manufacturer on their product is training, and it is well worth having, but it is not an audited standard. Having a method of your own is not a standard either — it is the thing above, and we call it by its name. And the counting approval covering the counting does not mean it covers the rest of the system.
The three get told as if they were the same thing often enough, and in a comparison of bids that is exactly what makes the one with the least of it, and the best story about it, win.
Get started
Ask us for the papers.
Tell us what file you have in front of you and we will send you the certificates that apply, with their scope and their expiry date. If one is missing for what you need, we tell you before you find out yourself.