Skip to content
  1. Home
  2. Trust & security
trust center

The controls behind the platform. And the evidence for them.

endlayer is developed and operated by Holistic AI, a company that helps enterprises govern their AI. We hold ourselves to the standard of evidence we ask of them: our security programme is independently audited, and the underlying reports, certificates and policies are available to customers and prospects under a mutual NDA.

ISO/IEC 27001:2022SOC 2 Type 2UK GDPR & Data Protection Act 2018ISO/IEC 42001 · audit scheduled
92/93
ISO 27001 Annex A controls in scope
4/5
SOC 2 Trust Services Criteria examined
0
nonconformities at our 2026 certification audit
39
documents available under mutual NDA
compliance

Four frameworks. Three held, one under way.

Certified

ISO/IEC 27001:2022

Information security management system supporting the development and deployment of the Holistic AI platform, which includes endlayer.

Report available

SOC 2 Type 2

Design and operating effectiveness across Security, Availability, Confidentiality and Privacy.

Compliant

UK GDPR & Data Protection Act 2018

Holistic AI Limited is the data controller where personal data is provided directly through our website; the Information Commissioner's Office (ICO) is our supervisory authority. Under a customer MSA we act as data processor. Full wording in the FAQ.

In progress

ISO/IEC 42001

AI management system. We do not hold this certification today; work towards it is under way and we will update this page once it is certified.

overview

What the certificate covers. Control by control.

Here you can review the frameworks we are certified against, the controls we operate, and the documents we hold. The documents themselves are released only after a mutual NDA is in place: use request access and tell us which ones you need.

ISO/IEC 27001:2022 · Annex A coverage
92of 93 in scope
A.5 Organisational controls37 of 37
A.6 People controls8 of 8
A.7 Physical controls14 of 14
A.8 Technological controls33 of 34
A.8.30 Outsourced development excluded as not applicable

Controls in scope per ISO/IEC 27001:2022 Annex A theme, as set out in our Statement of Applicability. A.8.30 Outsourced development is the single exclusion: we do not outsource development. Certification runs on a three-year cycle with annual surveillance audits in between; our certification audit closed with no nonconformities and no opportunities for improvement raised.

framework coverage by control domain
Control domainISO 270011SOC 22
Organisational securityCoveredCovered
People securityCoveredCovered
Infrastructure securityCoveredCovered
Product securityCoveredCovered
Access controlCoveredCovered
Data and privacyCoveredCovered
Incident response and continuityCoveredCovered

1 ISO/IEC 27001 coverage reflects the Annex A controls listed in our Statement of Applicability. A.8.30 Outsourced development is excluded as not applicable.
2 SOC 2 coverage reflects the Security, Availability, Confidentiality and Privacy criteria. Processing Integrity was not among the criteria examined.

security programme

32 controls we operate. Each traced to the standard.

Certification is a point in time. These are the practices that keep the controls working in between audits, all of them examined during our ISO/IEC 27001:2022 certification audit. Each control is annotated with the Annex A control or management-system clause it implements, so a reviewer can trace a statement back to the standard.

Organisational security4 controls

  • Information Security CommitteeA.5.2, A.5.4

    Senior management, engineering and operations, legal and information security review the ISMS at least annually.

  • Risk managementClause 6.1.2, 6.1.3

    Risks are identified, assessed and treated under a documented policy, with a register maintained continuously.

  • Internal auditClause 9.2

    An internal ISMS audit runs at least annually; findings and corrective actions are reviewed by management.

  • Policy managementA.5.1, A.5.37

    All policies are version-controlled, reviewed annually and acknowledged by staff at onboarding.

People security4 controls

  • Background screeningA.6.1

    New joiners are screened before access is granted.

  • Confidentiality agreementsA.6.2, A.6.6

    All personnel are bound by confidentiality obligations and a code of business conduct.

  • Security awareness trainingA.6.3

    Delivered at onboarding and refreshed on an ongoing basis.

  • Joiner, mover, leaverA.5.18, A.6.5

    Access is provisioned and revoked through a documented process tied to employment status.

Infrastructure security6 controls

  • Cloud hostingA.5.23

    Infrastructure runs on Amazon Web Services, in Europe (London) by default. US customers are hosted in US East (Ohio) or, where required, on Google Cloud Platform.

  • EncryptionA.8.24

    Encrypted in transit (TLS 1.2+) and at rest (AES-256 via AWS KMS), with dedicated keys for credential storage and key rotation at least every 12 months, per our Encryption Policy.

  • Network securityA.8.20–A.8.23

    Network segregation, secure network services and web filtering are in place.

  • Logging and monitoringA.8.15–A.8.17

    System activity is logged and monitored, with clock synchronisation across systems.

  • Vulnerability managementA.8.8

    Technical vulnerabilities are identified, tracked and remediated on a defined schedule.

  • Backup and redundancyA.8.13, A.8.14, A.5.30

    Documented backup, recovery and disaster recovery procedures with redundant infrastructure, to a recovery objective of 72 hours. Data is replicated across multiple regions.

Product security6 controls

  • Secure development lifecycleA.8.25, A.8.28

    Development follows a documented SDLC policy with secure coding standards and code review.

  • Environment separationA.8.31

    Development, test and production environments are kept separate.

  • Security testingA.8.29

    Security testing is performed during development and acceptance.

  • Penetration testingA.8.8, A.8.29

    Independent penetration testing is performed annually. The executive summary is available under NDA.

  • Change managementA.8.32

    Changes to production are reviewed, approved and tracked.

  • Access to source codeA.8.4

    Repository access is restricted and reviewed.

Access control4 controls

  • Least privilegeA.5.15, A.8.3

    Access is granted on a need-to-know basis and reviewed periodically.

  • Privileged accessA.8.2, A.8.18

    Administrative rights are restricted, logged and separately approved.

  • Secure authenticationA.5.17, A.8.5

    Platform sign-in, single sign-on and user directory management run through WorkOS. Access to systems holding customer data is restricted and reviewed under our Access Control Procedure.

  • Customer data accessA.5.15, A.5.18

    Limited to a small number of authorised personnel under confidentiality obligations.

Data and privacy4 controls

  • Data residencyA.5.23, A.5.34

    Customer data is hosted in the UK by default. US customers are hosted in the United States. Transfers are covered by the safeguards in our Data Processing Agreement.

  • Retention and deletionA.5.33, A.8.10

    Data is retained only as long as necessary for the purpose it was collected for, or according to the timeline set out in the MSA. On termination or on request it is permanently deleted from storage, databases and backups under our secure deletion protocol.

  • Data classificationA.5.12, A.5.13

    Information is classified, labelled and handled according to sensitivity.

  • Special category dataA.5.34

    Not collected.

Incident response and continuity4 controls

  • Incident managementA.5.24–A.5.27

    Documented policy and procedure covering detection, assessment, response and post-incident learning.

  • Customer notificationA.5.26, A.6.8

    Confirmed incidents affecting customer data are notified within 72 hours, or within the timeline agreed in the MSA, under our Incident Management Procedure and Personal Data Breach Notification Policy.

  • Business continuityA.5.29, A.5.30

    BCDR plans are documented and maintained for the platform.

  • Vendor riskA.5.19, A.5.20, A.5.22

    Suppliers are assessed before onboarding and reviewed under our Vendor Management Procedure.

documents

39 documents under NDA. Named, so you know what exists.

Everything below is released under a signed mutual NDA, except where marked public. We publish the full document titles so you can see exactly what exists before you request anything.

certifications

  • ISO/IEC 27001:2022 Certificate of RegistrationHolistic AI Inc
    Request access

audit reports

isms

policies

procedures and plans

questionnaires

  • Security questionnairesWe complete SIG, CAIQ, VSA, HECVAT and customer-specific formats on request.
    Request access

legal

  • Data Processing AgreementA standard template exists, including international transfer safeguards.
    Request access
  • Terms & ConditionsPublic, no NDA required
    View →
  • Privacy PolicyPublic, no NDA required
    View →
  • Cookies PolicyPublic, no NDA required
    View →
subprocessors

Who may process customer data. Four providers, each assessed.

Third parties that may process customer data on our behalf. Each is assessed under our Vendor Management Procedure before onboarding and reviewed periodically. We notify customers in advance of material changes: email we@holisticai.com to be added to that list.

  • Amazon Web ServicesAWSCloud infrastructure and data hosting

    Hosting, backup and disaster recovery for the platform. Europe (London) is the default region; US customers are hosted in US East (Ohio).

    UK · US
  • Google Cloud PlatformGCPCloud infrastructure and data hosting

    Alternative hosting for US customers where required in place of AWS.

    US
  • WorkOSWorkOSAuthentication and user management

    Sign-in, single sign-on and user directory management for the platform.

    US
  • Twilio SendGridTwilio SendGridTransactional email

    Service notifications and account messages sent from the platform.

    US

Locations shown are the jurisdictions in which each provider operates for Holistic AI. Transfers outside the UK and EEA are covered by the transfer safeguards in our standard Data Processing Agreement, available under NDA.

frequently asked

The questions reviewers ask. Answered in advance.

If your question is not here, ask us directly.

document access

How do I get access to your audit reports?

Request access and tell us your name, company and which documents you need. We send our standard mutual NDA for e-signature, or use the one already in place with your company. Access is granted within two business days, usually the same day.

Why are the reports behind an NDA rather than published?

Our audit reports and policies describe how we secure our systems in detail. That detail is useful to a customer assessing us and equally useful to an attacker, so we share it under a mutual NDA rather than publishing it openly.

Do you complete security questionnaires?

Yes. Send it to we@holisticai.com. Reviewing our SOC 2 report and ISO 27001 documentation first will usually answer most of it.

security

What does your ISO/IEC 27001 certificate actually cover?

The information security management system supporting the development and deployment of the Holistic AI platform, covering our Engineering, IT, HR, Admin, Customer Support, Sales and Marketing functions. A certification is only as meaningful as its scope, so the full scope statement and Statement of Applicability are both available under NDA.

How do you keep the certification current?

Certification runs on a three-year cycle with annual surveillance audits by our certification body in between, and we run our own internal ISMS audit and management review at least annually. Certification is a point in time; the surveillance cycle is what keeps it honest.

How often do you run penetration tests?

Annually, by an independent third party. The executive summary is available under NDA; request it alongside our audit reports.

Are you certified to ISO/IEC 42001?

Not yet. Our ISO/IEC 42001 certification audit is scheduled for the coming months and we will update this page when it completes. We would rather tell you where we actually are than imply a certificate we do not hold.

I found a security bug. How do I report it?

Email we@holisticai.com with enough detail for us to reproduce it. We acknowledge every report and keep you updated until it is resolved. Please do not access data that is not yours, and do not degrade the service for others while testing.

data handling

Do you train models on customer data?

No. We do not use customer data to train models. We do not build or train models of our own. The platform assesses and governs the AI systems our customers build, buy or run; it does not learn from the data it handles. Your data is used only to run the service for you.

How quickly would you tell us about a security incident?

Within 72 hours of a confirmed incident affecting your data, or within the timeline agreed in your MSA if that is shorter. Notification runs under our Incident Management Procedure and Personal Data Breach Notification Policy.

Where is customer data stored?

By default, in the UK: Amazon Web Services, Europe (London). US customers are hosted in the United States: AWS US East (Ohio), or Google Cloud Platform where required. Data is replicated across multiple regions for redundancy and disaster recovery.

Will you sign a DPA, and are you a controller or a processor?

Yes. A standard Data Processing Agreement template exists, including international transfer safeguards, available on request. Holistic AI Limited is the data controller where customers provide personal data directly through the website; in such circumstances the Information Commissioner's Office (ICO) is our supervisory authority. Where we enter into an MSA with a customer, Holistic AI Limited acts as a data processor and processes personal data solely on the customer's documented instructions, in accordance with the data protection provisions in the MSA and, where required, a Data Processing Agreement. Our processing activities are therefore undertaken in accordance with the UK GDPR and the Data Protection Act 2018, as applicable to our role as either controller or processor.

What happens to our data when the contract ends?

Data is retained only as long as necessary for the purpose it was collected for, or according to the timeline set out in your MSA. Deletion is initiated on termination or on your request; your data is then permanently removed from storage, databases and backups using our secure deletion protocols. Written confirmation of deletion is available on request.

updates

What changed. Newest first.

Changes to our certifications, documents and subprocessor list.

  1. subprocessorsSubprocessor list published

    We now publish our full subprocessor list, with the purpose and operating jurisdiction of each. Email us to be added to the advance notification list for changes.

  2. complianceISO/IEC 42001 certification audit scheduled

    We will undergo an ISO/IEC 42001 audit for our AI management system in the coming months. We are not certified today; this page will be updated when the audit completes.

  3. complianceISO/IEC 27001:2022 certification achieved

    Our information security management system was certified against ISO/IEC 27001:2022 following a Stage 2 audit by our certification body, with no nonconformities raised. The certificate, the audit report and the Statement of Applicability are available under NDA.

  4. complianceSOC 2 Type 2 report published

    Our SOC 2 Type 2 report covering Security, Availability, Confidentiality and Privacy is available to customers and prospects under NDA.

start a review

Tell us which documents you need.

start with endlayer

Take control of the AI already in your company.

It is already installed on the laptops. You can see all of it by this afternoon.

activity4h slices
30d ago22d15d7dnow