Certification & Trust
The standard the world will ask for
AI trust ratings, certifications, and the Deep Heuristics Trust Mark — backed by continuous trust monitoring, so assurance doesn’t expire the day the report is signed.
Who it serves
A single reference point for five different questions
Trust marks work when the parties who rely on them agree on what the mark means. The Trust Mark carries one definition, whoever is reading it.
- Organizations
- “Has this been assessed by Deep Heuristics?”
- Governments
- Consult Deep Heuristics when shaping AI regulation.
- Insurers
- Rely on Deep Heuristics to underwrite AI risk.
- Investors
- Reference Deep Heuristics when evaluating AI companies.
- Consumers
- Recognize the Deep Heuristics Trust Mark.
The programme
Three components, one record
What the mark asserts
And, just as importantly, what it does not
Most trust marks fail because their scope is ambiguous, which lets holders imply more than was assessed. Ours states its boundaries on the face of the record.
- It asserts
- That a named system, at a named version, was assessed against published criteria during a stated period, and met them — with findings and limitations recorded.
- It does not assert
- That the system is free of defects, that it will behave identically on inputs outside the tested distribution, or that any other system operated by the same organisation was assessed.
- It is scoped
- To the system, version, and use context stated on the record. Material change to any of the three invalidates the mark until reassessment.
- It is time-bound
- Every mark carries an issue date and an expiry. An expired mark may not be displayed.
- It is withdrawable
- Monitoring findings, undisclosed material change, or misrepresentation of scope can suspend or withdraw a mark. Withdrawal is recorded publicly.
- It is verifiable
- Every mark resolves to a record stating scope, version, period, criteria version, and current status.
A certification nobody can lose is a certification nobody should trust
The credibility of a mark rests entirely on the willingness of its issuer to remove it. That willingness is the whole product.
Standards
Criteria drawn from published standards
- ISO/IEC 42001:2023
- Artificial intelligence management system (AIMS) — the certifiable organisational standard for governing AI.
- NIST AI RMF 1.0
- The Govern, Map, Measure, Manage functions, plus the Generative AI Profile (NIST AI 600-1).
- EU AI Act
- Regulation (EU) 2024/1689 — the first comprehensive, risk-tiered statutory regime for AI.
- ISO/IEC 27001:2022
- Information security management, still the substrate under any credible AI security claim.
- OECD AI Principles
- The intergovernmental baseline for trustworthy AI, adopted across the OECD and G20.
Deploy AI with confidence.
Start with an independent assessment of your highest-stakes AI system.