ISO/IEC 27001:2022
Information security management system supporting the development and deployment of the Holistic AI platform, which includes endlayer.
endlayer is developed and operated by Holistic AI, a company that helps enterprises govern their AI. We hold ourselves to the standard of evidence we ask of them: our security programme is independently audited, and the underlying reports, certificates and policies are available to customers and prospects under a mutual NDA.
Information security management system supporting the development and deployment of the Holistic AI platform, which includes endlayer.
Design and operating effectiveness across Security, Availability, Confidentiality and Privacy.
Holistic AI Limited is the data controller where personal data is provided directly through our website; the Information Commissioner's Office (ICO) is our supervisory authority. Under a customer MSA we act as data processor. Full wording in the FAQ.
AI management system. We do not hold this certification today; work towards it is under way and we will update this page once it is certified.
Here you can review the frameworks we are certified against, the controls we operate, and the documents we hold. The documents themselves are released only after a mutual NDA is in place: use request access and tell us which ones you need.
Controls in scope per ISO/IEC 27001:2022 Annex A theme, as set out in our Statement of Applicability. A.8.30 Outsourced development is the single exclusion: we do not outsource development. Certification runs on a three-year cycle with annual surveillance audits in between; our certification audit closed with no nonconformities and no opportunities for improvement raised.
| Control domain | ISO 270011 | SOC 22 |
|---|---|---|
| Organisational security | Covered | Covered |
| People security | Covered | Covered |
| Infrastructure security | Covered | Covered |
| Product security | Covered | Covered |
| Access control | Covered | Covered |
| Data and privacy | Covered | Covered |
| Incident response and continuity | Covered | Covered |
1 ISO/IEC 27001 coverage reflects the Annex A controls listed in our Statement of Applicability. A.8.30 Outsourced development is excluded as not applicable.
2 SOC 2 coverage reflects the Security, Availability, Confidentiality and Privacy criteria. Processing Integrity was not among the criteria examined.
Certification is a point in time. These are the practices that keep the controls working in between audits, all of them examined during our ISO/IEC 27001:2022 certification audit. Each control is annotated with the Annex A control or management-system clause it implements, so a reviewer can trace a statement back to the standard.
A.5.2, A.5.4Senior management, engineering and operations, legal and information security review the ISMS at least annually.
Clause 6.1.2, 6.1.3Risks are identified, assessed and treated under a documented policy, with a register maintained continuously.
Clause 9.2An internal ISMS audit runs at least annually; findings and corrective actions are reviewed by management.
A.5.1, A.5.37All policies are version-controlled, reviewed annually and acknowledged by staff at onboarding.
A.6.1New joiners are screened before access is granted.
A.6.2, A.6.6All personnel are bound by confidentiality obligations and a code of business conduct.
A.6.3Delivered at onboarding and refreshed on an ongoing basis.
A.5.18, A.6.5Access is provisioned and revoked through a documented process tied to employment status.
A.5.23Infrastructure runs on Amazon Web Services, in Europe (London) by default. US customers are hosted in US East (Ohio) or, where required, on Google Cloud Platform.
A.8.24Encrypted in transit (TLS 1.2+) and at rest (AES-256 via AWS KMS), with dedicated keys for credential storage and key rotation at least every 12 months, per our Encryption Policy.
A.8.20–A.8.23Network segregation, secure network services and web filtering are in place.
A.8.15–A.8.17System activity is logged and monitored, with clock synchronisation across systems.
A.8.8Technical vulnerabilities are identified, tracked and remediated on a defined schedule.
A.8.13, A.8.14, A.5.30Documented backup, recovery and disaster recovery procedures with redundant infrastructure, to a recovery objective of 72 hours. Data is replicated across multiple regions.
A.8.25, A.8.28Development follows a documented SDLC policy with secure coding standards and code review.
A.8.31Development, test and production environments are kept separate.
A.8.29Security testing is performed during development and acceptance.
A.8.8, A.8.29Independent penetration testing is performed annually. The executive summary is available under NDA.
A.8.32Changes to production are reviewed, approved and tracked.
A.8.4Repository access is restricted and reviewed.
A.5.15, A.8.3Access is granted on a need-to-know basis and reviewed periodically.
A.8.2, A.8.18Administrative rights are restricted, logged and separately approved.
A.5.17, A.8.5Platform sign-in, single sign-on and user directory management run through WorkOS. Access to systems holding customer data is restricted and reviewed under our Access Control Procedure.
A.5.15, A.5.18Limited to a small number of authorised personnel under confidentiality obligations.
A.5.23, A.5.34Customer data is hosted in the UK by default. US customers are hosted in the United States. Transfers are covered by the safeguards in our Data Processing Agreement.
A.5.33, A.8.10Data is retained only as long as necessary for the purpose it was collected for, or according to the timeline set out in the MSA. On termination or on request it is permanently deleted from storage, databases and backups under our secure deletion protocol.
A.5.12, A.5.13Information is classified, labelled and handled according to sensitivity.
A.5.34Not collected.
A.5.24–A.5.27Documented policy and procedure covering detection, assessment, response and post-incident learning.
A.5.26, A.6.8Confirmed incidents affecting customer data are notified within 72 hours, or within the timeline agreed in the MSA, under our Incident Management Procedure and Personal Data Breach Notification Policy.
A.5.29, A.5.30BCDR plans are documented and maintained for the platform.
A.5.19, A.5.20, A.5.22Suppliers are assessed before onboarding and reviewed under our Vendor Management Procedure.
Everything below is released under a signed mutual NDA, except where marked public. We publish the full document titles so you can see exactly what exists before you request anything.
Third parties that may process customer data on our behalf. Each is assessed under our Vendor Management Procedure before onboarding and reviewed periodically. We notify customers in advance of material changes: email we@holisticai.com to be added to that list.
Hosting, backup and disaster recovery for the platform. Europe (London) is the default region; US customers are hosted in US East (Ohio).
UK · USAlternative hosting for US customers where required in place of AWS.
USSign-in, single sign-on and user directory management for the platform.
USService notifications and account messages sent from the platform.
USLocations shown are the jurisdictions in which each provider operates for Holistic AI. Transfers outside the UK and EEA are covered by the transfer safeguards in our standard Data Processing Agreement, available under NDA.
If your question is not here, ask us directly.
Request access and tell us your name, company and which documents you need. We send our standard mutual NDA for e-signature, or use the one already in place with your company. Access is granted within two business days, usually the same day.
Our audit reports and policies describe how we secure our systems in detail. That detail is useful to a customer assessing us and equally useful to an attacker, so we share it under a mutual NDA rather than publishing it openly.
Yes. Send it to we@holisticai.com. Reviewing our SOC 2 report and ISO 27001 documentation first will usually answer most of it.
The information security management system supporting the development and deployment of the Holistic AI platform, covering our Engineering, IT, HR, Admin, Customer Support, Sales and Marketing functions. A certification is only as meaningful as its scope, so the full scope statement and Statement of Applicability are both available under NDA.
Certification runs on a three-year cycle with annual surveillance audits by our certification body in between, and we run our own internal ISMS audit and management review at least annually. Certification is a point in time; the surveillance cycle is what keeps it honest.
Annually, by an independent third party. The executive summary is available under NDA; request it alongside our audit reports.
Not yet. Our ISO/IEC 42001 certification audit is scheduled for the coming months and we will update this page when it completes. We would rather tell you where we actually are than imply a certificate we do not hold.
Email we@holisticai.com with enough detail for us to reproduce it. We acknowledge every report and keep you updated until it is resolved. Please do not access data that is not yours, and do not degrade the service for others while testing.
No. We do not use customer data to train models. We do not build or train models of our own. The platform assesses and governs the AI systems our customers build, buy or run; it does not learn from the data it handles. Your data is used only to run the service for you.
Within 72 hours of a confirmed incident affecting your data, or within the timeline agreed in your MSA if that is shorter. Notification runs under our Incident Management Procedure and Personal Data Breach Notification Policy.
By default, in the UK: Amazon Web Services, Europe (London). US customers are hosted in the United States: AWS US East (Ohio), or Google Cloud Platform where required. Data is replicated across multiple regions for redundancy and disaster recovery.
Yes. A standard Data Processing Agreement template exists, including international transfer safeguards, available on request. Holistic AI Limited is the data controller where customers provide personal data directly through the website; in such circumstances the Information Commissioner's Office (ICO) is our supervisory authority. Where we enter into an MSA with a customer, Holistic AI Limited acts as a data processor and processes personal data solely on the customer's documented instructions, in accordance with the data protection provisions in the MSA and, where required, a Data Processing Agreement. Our processing activities are therefore undertaken in accordance with the UK GDPR and the Data Protection Act 2018, as applicable to our role as either controller or processor.
Data is retained only as long as necessary for the purpose it was collected for, or according to the timeline set out in your MSA. Deletion is initiated on termination or on your request; your data is then permanently removed from storage, databases and backups using our secure deletion protocols. Written confirmation of deletion is available on request.
Changes to our certifications, documents and subprocessor list.
We now publish our full subprocessor list, with the purpose and operating jurisdiction of each. Email us to be added to the advance notification list for changes.
We will undergo an ISO/IEC 42001 audit for our AI management system in the coming months. We are not certified today; this page will be updated when the audit completes.
Our information security management system was certified against ISO/IEC 27001:2022 following a Stage 2 audit by our certification body, with no nonconformities raised. The certificate, the audit report and the Statement of Applicability are available under NDA.
Our SOC 2 Type 2 report covering Security, Availability, Confidentiality and Privacy is available to customers and prospects under NDA.
It is already installed on the laptops. You can see all of it by this afternoon.