
our reason to exist
Our mission
To provide high-quality services to local and international organisations, turning our knowledge and experience into added value for their own benefit, with ethics and client satisfaction as our priorities.
SORT was built on the reputation of its partners, with more than ten years as trusted providers of security and information technology services.
+15
successful certification projects
5
countries with certified clients
+25
long-standing clients
+1200
hours of training delivered
what we do
Our years of experience let us offer complete security solutions, designed to answer the threats organisations actually face rather than the ones in a catalogue.
The service portfolio covers the compliance, security and assessment requirements of any organisation, and helps identify, evaluate and improve its corporate security system.
We work as a partner, not a vendor: we join the client’s security committee and stay with the management system after certification, which is when most projects fall apart.


our reason to exist
To provide high-quality services to local and international organisations, turning our knowledge and experience into added value for their own benefit, with ethics and client satisfaction as our priorities.

always on the horizon
To be a company in constant growth, a leader in the markets where it operates, with an international presence, known for delivering high-quality services, offering its people opportunities for personal and professional development, and making a positive contribution to society.

what sets us apart
what defines us
01
Services that add real value and fully meet the client’s needs and expectations.
02
Professional ethics and the highest standards of conduct in everything we do.
03
We innovate in processes, services and solutions to stay ahead of the curve.
04
We help our clients reach the highest international standards — the state of the art in each field.
who we are

Managing Partner
ISO/IEC 27001 Lead Auditor
Has led SORT since it was founded in 2017. An ISO/IEC 27001 Lead Auditor, he has run implementation and certification projects in healthcare, banking, logistics and technology across Uruguay, Panama, the Bahamas, Puerto Rico and the United States.
LinkedIn — Gabriel Fernándezwho will work with you
The stable core that takes part in the projects. Senior profiles in management, audit and information security.
Beyond the senior core, we work with a network of cybersecurity and software engineering professionals with varied profiles —technical, management and audit— holding PMP, ISO/IEC 27001 Lead Auditor, CISM and CEH certifications, among others. We bring in whoever the project actually calls for, instead of forcing every problem onto whichever profile happens to be available.
frequently asked questions
Senior consultants, not junior profiles learning on your organisation. The managing partner takes part in every project and the assigned team stays the same from start to finish: no rotation, and no layers of intermediation between the person who gathers the facts and the person who decides.
ISO/IEC 27001 Lead Auditor and CISSP at partner level, and across the wider network PMP, ISO/IEC 27001 Lead Auditor, CISM and CEH, among others. For each project we bring in the right profile —technical, management or audit— rather than forcing the problem onto whoever is free.
No, and it could not: accreditation rules prevent a certification body from advising the organisation it later audits. We implement the system and support the process; the certificate is issued by an accredited body chosen by the client. That separation is precisely what makes the certificate worth something to a third party.
Healthcare, banking and financial groups, logistics and postal operations, technology and electronic invoicing, fintech, manufacturing and retail. Projects have been delivered in Uruguay, the United States, Panama, the Bahamas and Puerto Rico, with the same methodology and a blended on-site and remote approach.
That is where most projects fall apart. The certificate requires annual surveillance audits and recertification every three years, and a system that is not maintained loses it. We support that stage: keeping the risk analysis current, internal audits, management review and preparation for each external milestone. Several of our clients have worked with us continuously since 2017.
your business partner