Assurance Platform
A record a third party can reconstruct
Tamper-evident retention of what was tested, when, against which version, by whom, and with what result — because an assurance opinion is only as good as the record behind it.
Capabilities
What this module provides
Immutable audit trail
Evidence is written once and retained with integrity verification. Later corrections are appended, never substituted.
Version binding
Each artefact is bound to the exact model, dataset, prompt, and configuration version it came from.
Chain of custody
Who collected each artefact, under what authorisation, and who has accessed it since.
Regulator-ready export
Structured export of the evidence set supporting any conclusion, in the form a supervisory authority expects.
Data handling
Your evidence is your evidence
Client data is segregated, encrypted in transit and at rest, retained for a contractually defined period, and never used to train models. Access is least-privilege and logged. Where testing requires production data, we work from the minimum sufficient extract.
- Client-segregated storage
- Encryption in transit and at rest
- Least-privilege access
- Access logging
- Contractual retention limits
- No secondary use for training
Standards
Anchored to published criteria
- ISO/IEC 27001:2022
- Information security management, still the substrate under any credible AI security claim.
- ISO/IEC 42001:2023
- Artificial intelligence management system (AIMS) — the certifiable organisational standard for governing AI.
- EU AI Act
- Regulation (EU) 2024/1689 — the first comprehensive, risk-tiered statutory regime for AI.
Other platform modules
Deploy AI with confidence.
Start with an independent assessment of your highest-stakes AI system.