Wiremind Logo

Amir Ali Mashayekhi

Head of Security and IT

Outline

Subscribe to our newsletter!

Receive exclusive updates on Wiremind's products, customer stories, and all upcoming events.

Amir Ali Mashayekhi

Head of Security and IT

Security at Wiremind: Building Trust Through a Systemic Approach

May 21, 2025
-
6
min read

In today's digital landscape, security isn't just a feature - it's the foundation upon which lasting business relationships are built. At Wiremind, we understand that as a B2B SaaS provider serving international markets, our clients entrust us with their most valuable assets: their data, their operations, and ultimately, their business success.

As the Head of Information Security and IT at Wiremind, as well as our Data Protection Officer (DPO), I've made it our security team's mission to ensure this trust is well-placed. Together, we've developed a comprehensive security framework that touches every aspect of our organization, working closely with teams across Wiremind to implement and maintain robust protection measures.

Why Security Matters in the B2B SaaS Landscape

The B2B relationships we cultivate at Wiremind are characterized by high-value contracts, long-term engagements, and the handling of valuable data. Our enterprise clients rightfully expect robust, transparent security measures that protect their interests and comply with global standards.

When clients choose Wiremind, they're making a profound decision to intertwine their critical operations with our systems. They're entrusting us with their operational backbone, proprietary data, customer relationships, and ultimately their business reputation. This level of trust demands more than technical competence; it requires an unwavering commitment to transparency and integrity. As security leaders, we've evolved beyond the traditional defensive mindset. We don't merely erect digital fortifications - we architect environments where trust can flourish organically.

Every security control we implement, every audit we complete, and every protocol we establish serves a dual purpose: protecting valuable assets while simultaneously reinforcing our clients' confidence in Wiremind. This perspective elevates security from a cost center to a business differentiator that enables growth, innovation, and lasting partnerships.

We've cultivated this trust through transparency, consistency, and proactive communication. Our security documentation is clear and accessible. We welcome client security audits and questionnaires, viewing them as opportunities to demonstrate our capabilities and address concerns directly. When potential vulnerabilities are identified, we communicate promptly and provide clear remediation timelines. Our enterprise clients often have their own security and compliance obligations to meet. By maintaining rigorous security standards, we help them fulfill these responsibilities and protect their reputation with their own customers. This creates a chain of trust that extends beyond our direct relationship.

As Wiremind has grown, so too has the importance of our security operations. What began as essential protection has evolved into a strategic advantage, allowing us to confidently enter new markets and serve clients with increasingly complex security requirements.

"Security at Wiremind isn't just about protection - it's about enabling trust, strengthening relationships, and creating the confidence our clients need to innovate alongside us”, explains Charles Pierre, Co-founder and CTO at Wiremind.

Our Security Philosophy: Keep it SAS

At the heart of our approach is a philosophy we call, "Keep it SAS: Secure, Available, Simple”

  • Keep it Secure: We maintain an excellent security posture through comprehensive controls, regular testing, and continuous improvement.
  • Keep it Available: We ensure our SaaS applications are sustainable and available when our clients need them most.
  • Keep it Simple: We design our IT workflows to be both secure and productive, giving our team the freedom to work efficiently without compromising safety.

As Head of Information Security, I firmly believe that security isn't about creating barriers - it's about building bridges of trust. We implement robust security measures while ensuring our systems remain available and our processes remain simple. This balance is what allows us to protect our clients' data without hindering their operations or innovation.

Our security philosophy guides everything we do, from how we build our products to how we engage with our clients and partners.

Our Security Framework

Certification and Compliance That Exceeds Expectations

Our commitment to security excellence is validated through:

  • ISO 27001:2022 Certification:  I coordinated our security team's successful completion of two rigorous ISO 27001 audits, with our most recent certification being under the updated ISO 27001:2022 standard. This certification isn't just a badge, it represents our systematic approach to managing sensitive company and customer information. The certification process required us to demonstrate our Information Security Management System (ISMS) meets international standards across all aspects of our business, from risk assessment methodologies to technical controls and regular management reviews. This achievement validates our comprehensive approach to security governance.
  • SOC 2 Type II Reporting: Our security team has recently completed the extensive SOC 2 Type II examination process, which evaluates controls over an extended period rather than just a point in time. This comprehensive report validates our systems across four critical trust categories: security, availability, confidentiality, and processing integrity. The independent auditors thoroughly examined our control environment, communication protocols, risk management processes, monitoring activities, and information security practices across all these dimensions. By maintaining SOC 2 Type II compliance, we provide our clients with transparent, third-party verification that their data is not only properly protected but also processed with integrity within our systems.
  • GDPR Compliance: As the Data Protection Officer (DPO) at Wiremind, I've established a culture where data protection is everyone's responsibility. Rather than centralizing all compliance efforts, I've worked to ensure that GDPR awareness and implementation extends across all departments. Our comprehensive data protection measures respect and safeguard personal information by design and by default. Through regular training, clear policies, and collaborative processes, every team member understands their role in maintaining GDPR compliance, giving our clients confidence that their data is handled with the utmost care and legal compliance at every touchpoint.

Our global perspective ensures we meet security expectations across different geographic regions, anticipating the specific needs of our international client base. And this is certainly not the end of our compliance journey. We operate with a continuous improvement mindset, constantly evaluating emerging security frameworks, standards, and regulations. As new compliance requirements emerge in different regions, we're already preparing to adapt and enhance our security posture accordingly. This proactive approach allows us to stay ahead of regulatory changes and maintain our commitment to the highest security standards worldwide.

A Cross-Functional Security Approach

At Wiremind, I work hand-in-hand with every department - from HR and Finance to Development, Platform, Sales, and Customer Success - to embed security into every layer of our organization. Security is not an afterthought; it's a shared mission that starts with me and touches every aspect of our operations.

Leading Collaboration Across Departments

Product & Development

I collaborate closely with our development teams to embed security into the foundation of every product we build. My contributions support the adoption of secure coding practices and the integration of automated security testing within our CI/CD pipelines to catch issues early in the development lifecycle.

In addition to preventive measures, I help coordinate vulnerability scanning across our applications and services to continuously assess our exposure to known threats. We also regularly conduct penetration testing, both internally and with external partners, to simulate real-world attack scenarios and identify areas for improvement.

By being involved throughout the product lifecycle, I help ensure that security is not just a layer on top, but a core design principle that enhances resilience, availability, and threat mitigation from the ground up.

Platform & Infrastructure

I contribute to the ongoing efforts of our infrastructure and DevOps teams by helping shape and reinforce key security practices, such as identity and access management (IAM), least-privilege principles, and role-based access controls. My role supports the implementation of these controls in a way that balances operational needs with strong security posture.

In collaboration with the team, I help integrate and maintain monitoring and alerting systems that provide critical visibility across our environments. This includes deploying and tuning intrusion detection systems (IDS) and endpoint detection and response (EDR) solutions to detect, investigate, and contain potential threats at both the network and device levels.

Having a dedicated platform team that delivers internal tools for engineers enables a structured workflow with security at its core. This includes automated encryption management, Web Application Filtering setup, and backup & restore tests. As a result, our software engineering teams can focus on product quality while maintaining a strong security posture. This organization gives me a complete view of everything happening at Wiremind and how it's being done.

By contributing to these shared efforts, I help ensure that our infrastructure is not only securely configured, but also actively monitored and resilient against evolving threats.

Sales & Business Development

Security often begins with the first customer conversation. I support our Sales and Customer Success teams by providing detailed responses to RFPs, enabling them to build trust through transparency. I also participate in high-stakes client engagements, ensuring security concerns are addressed from the outset.

Human Resources & Finance

Security isn't just technical, it's human and procedural too. I guide HR in implementing strict access protocols for sensitive personal data and support Finance in safeguarding critical systems with compliance-focused controls. Through regular collaboration, we minimize risk across all internal processes.

Awareness & Training

Security is a shared mindset. I lead initiatives to embed this culture into Wiremind’s DNA, starting with onboarding and reinforced through regular trainings and internal communications.

Client Engagement

I maintain a direct, transparent relationship with our clients to foster confidence and partnership. Whether it's during onboarding or routine security reviews, I remain accessible to discuss policies, respond to audits, and adapt to specific client requirements.

Client-Focused Onboarding

Our security team actively participates in onboarding new clients, ensuring their concerns are addressed and any bespoke security needs are met from day one.

Feedback-Informed Roadmap

Client feedback plays a critical role in shaping our security roadmap. By continuously incorporating their insights, we evolve our strategy to align with their expectations and emerging threats.

Looking Ahead: The Future of Security at Wiremind

Our security journey continues to evolve as we grow. Here’s a peek at the next chapter of security at Wiremind:

  • Expanding Certification Portfolio: We're actively exploring additional certifications to meet the needs of new markets and industries. We're monitoring the European NIS 2 Directive requirements to ensure we're prepared to meet these enhanced cybersecurity standards as they become applicable to our operations.
  • Global Security Posture: We're deepening our security capabilities across continents to support our international growth.
  • Investment in People and Technology: We're continuously investing in both our security team and cutting-edge technologies to stay ahead of evolving threats.

Security as a Partnership

At Wiremind, we believe that true security is built on transparency, reliability, and collaboration. Our dedication goes beyond mere compliance - it's about creating partnerships built on trust and continuous improvement.

We invite open dialogue with our clients and partners about security concerns and requirements. Together, we can build not just secure systems, but secure, lasting relationships.

To learn more Security at Wiremind, please visit our Security page.

Other resources you might like.

Curious to dig deeper? Discover our articles that give you an insider’s view into the modern technologies in passenger transportation at Wiremind.