ISO/IEC 27001 does not certify a building but an information security management system (ISMS): documented processes, audited by an accredited body and renewed (annual surveillance audit, recertification every 3 years).
In practice it covers risk governance, physical and logical access control, incident and continuity management, and supplier security, via the Annex A controls. For a customer, it is evidence that a managed security program exists, not just locks.
Distinguish it from other frameworks: HDS certification (mandatory for health data, built on ISO 27001), PCI DSS (payment card data), SOC 2 (US audit report), and the Tier level (which measures availability, not security). Ask for the certificate and above all its scope: it must cover the site that hosts you.