Security
ISO 27001, honestly.
Short version: we are in the middle of our ISO 27001 certification. Not certified yet. This page exists because we would rather tell you where we actually stand than put a badge in the footer and hope nobody asks.
Certification in progress
What that means in practice
An ISMS is not a document you write once, it is how the company runs. We are building ours along ISO 27001 and doing the audit process properly instead of rushing it. Some of it was in place long before we ever talked to an auditor, because a control plane for enterprise AI access that does not take security seriously would be a bit absurd.
Already in place today
- SSO and role-based access on every part of the platform, no shared accounts anywhere
- Full audit trail for every tool call an AI agent makes through Loopthink
- Encryption in transit and at rest, secrets never stored in plaintext
- All production infrastructure in the EU, operated under European control
- Least-privilege access for our own team, reviewed regularly
Working on it
- Formal ISMS documentation and risk management along ISO 27001 Annex A
- External audit cycle with an accredited certification body
- Structured vendor and supplier assessments
Security questionnaire? Send it over.
If your security team wants details before the certificate lands, we get it. Send us your questionnaire or book a call with the people who actually built the platform, not a sales deck.
Talk to us