Subprocessor list published
Subprocessors
August 2026
We now publish our full subprocessor list, with the purpose and operating jurisdiction of each. Email us to be added to the advance notification list for changes.
Trust Center
Holistic AI helps enterprises govern their AI. We hold ourselves to the standard of evidence we ask of them: our security programme is independently audited, and the underlying reports, certificates and policies are available to customers and prospects under a mutual NDA.
92/93
ISO 27001 Annex A controls in scope
4/5
SOC 2 Trust Services Criteria examined
0
Nonconformities at our 2026 certification audit
39
Documents available under mutual NDA
ISO/IEC 27001:2022
SOC 2 Type 2
UK GDPR
ISO/IEC 42001 — audit scheduled
Here you can review the frameworks we are certified against, the controls we operate, and the documents we hold. The documents themselves are released only after a mutual NDA is in place — use request access and tell us which ones you need.
92 of 93 in scope
A.5Organisational controls
37 of 37 controls in scope
A.6People controls
8 of 8 controls in scope
A.7Physical controls
14 of 14 controls in scope
A.8Technological controls
33 of 34 controls in scope
1 excluded as not applicable
Controls in scope per ISO/IEC 27001:2022 Annex A theme, as set out in our Statement of Applicability. A.8.30 Outsourced development is the single exclusion — we do not outsource development. Certification runs on a three-year cycle with annual surveillance audits in between; our certification audit closed with no nonconformities and no opportunities for improvement raised.
| Control domain | ISO 270011 | SOC 22 |
|---|---|---|
| Organisational security | Covered | Covered |
| People security | Covered | Covered |
| Infrastructure security | Covered | Covered |
| Product security | Covered | Covered |
| Access control | Covered | Covered |
| Data and privacy | Covered | Covered |
| Incident response and continuity | Covered | Covered |
Certified
Information security management system supporting the development and deployment of the Holistic AI platform.
Report available
Design and operating effectiveness across Security, Availability, Confidentiality and Privacy.
Compliant
Holistic AI Limited is the data controller where personal data is provided directly through our website — the Information Commissioner’s Office (ICO) is our supervisory authority. Under a customer MSA we act as data processor. Full wording
In progress
AI management system. We do not hold this certification today; work towards it is under way and we will update this page once it is certified.
Amazon Web Services · Cloud infrastructure and data hosting
UK · US
Google Cloud Platform · Cloud infrastructure (US customers)
US
WorkOS · Authentication and user management
US
Twilio SendGrid · Transactional email
US
Transfers outside the UK and EEA are covered by the transfer safeguards in our standard Data Processing Agreement.
Request access and tell us which documents you need. We send our standard mutual NDA for e-signature, or use the one already in place with your company, and grant access once it is signed.
No. We do not use customer data to train models. We do not build or train models of our own — the platform assesses and governs the AI systems our customers build or buy, and does not learn from the data it handles.
Email we@holisticai.com with enough detail for us to reproduce it. We acknowledge every report and keep you updated until it is resolved. Please do not access data that is not yours or degrade the service for others while testing.
Security programme
Certification is a point in time. These are the practices that keep the controls working in between audits — all of them examined during our ISO/IEC 27001:2022 certification audit. Each control is annotated with the Annex A control or management-system clause it implements, so a reviewer can trace a statement back to the standard.
Senior management, engineering and operations, legal and information security review the ISMS at least annually.
Risks are identified, assessed and treated under a documented policy, with a register maintained continuously.
An internal ISMS audit runs at least annually; findings and corrective actions are reviewed by management.
All policies are version-controlled, reviewed annually and acknowledged by staff at onboarding.
New joiners are screened before access is granted.
All personnel are bound by confidentiality obligations and a code of business conduct.
Delivered at onboarding and refreshed on an ongoing basis.
Access is provisioned and revoked through a documented process tied to employment status.
Infrastructure runs on Amazon Web Services, in Europe (London) by default. US customers are hosted in US East (Ohio) or, where required, on Google Cloud Platform.
Encrypted in transit (TLS 1.2+) and at rest (AES-256 via AWS KMS), with dedicated keys for credential storage and key rotation at least every 12 months, per our Encryption Policy.
Network segregation, secure network services and web filtering are in place.
System activity is logged and monitored, with clock synchronisation across systems.
Technical vulnerabilities are identified, tracked and remediated on a defined schedule.
Documented backup, recovery and disaster recovery procedures with redundant infrastructure, to a recovery objective of 72 hours. Data is replicated across multiple regions.
Development follows a documented SDLC policy with secure coding standards and code review.
Development, test and production environments are kept separate.
Security testing is performed during development and acceptance.
Independent penetration testing is performed annually. The executive summary is available under NDA.
Changes to production are reviewed, approved and tracked.
Repository access is restricted and reviewed.
Access is granted on a need-to-know basis and reviewed periodically.
Administrative rights are restricted, logged and separately approved.
Platform sign-in, single sign-on and user directory management run through WorkOS. Access to systems holding customer data is restricted and reviewed under our Access Control Procedure.
Limited to a small number of authorised personnel under confidentiality obligations.
Customer data is hosted in the UK by default. US customers are hosted in the United States. Transfers are covered by the safeguards in our Data Processing Agreement.
Data is retained only as long as necessary for the purpose it was collected for, or according to the timeline set out in the MSA. On termination or on request it is permanently deleted from storage, databases and backups under our secure deletion protocol.
Information is classified, labelled and handled according to sensitivity.
Not collected.
Documented policy and procedure covering detection, assessment, response and post-incident learning.
Confirmed incidents affecting customer data are notified within 72 hours, or within the timeline agreed in the MSA, under our Incident Management Procedure and Personal Data Breach Notification Policy.
BCDR plans are documented and maintained for the platform.
Suppliers are assessed before onboarding and reviewed under our Vendor Management Procedure.
Everything below is released under a signed mutual NDA, except where marked public. We publish the full document titles so you can see exactly what exists before you request anything.
ISO/IEC 27001:2022 Certificate of Registration Holistic AI Inc
SOC 2 Type 2 Report Holistic AI Platform
ISO/IEC 27001:2022 Stage 2 Audit Report Holistic AI Inc
Penetration Test Executive Summary
Independent test performed annually.
Statement of Applicability
ISMS Manual
ISMS Scope Document
ISMS Information Security Roles & Responsibilities
Legal and Contractual Requirement Register
Organizational Structure
System Description
Acceptable Usage Policy
Code of Business Conduct Policy
Communications and Network Security Policy
Data Breach Notification Policy
Data Classification Policy
Data Protection Policy
Data Retention Policy
Encryption Policy
Endpoint Security Policy
Organisation of Information Security Policy
Personal Data Breach Policy
Personal Data Breach Notification Policy
Risk Management Policy
System Acquisition Policy
Access Control Procedure
Asset Management Procedure
Business Continuity Plan
Compliance Procedure
Human Resources Security Procedure
Incident Management Procedure
Operations Security Procedure
Physical and Environmental Security Procedure
Software Development Life Cycle Procedure
Vendor Management Procedure
Disaster Recovery Plan
Backup, recovery and disaster recovery documentation.
New Hire Policy Acknowledgement
Security questionnaires
We complete SIG, CAIQ, VSA, HECVAT and customer-specific formats on request.
Data Processing Agreement
A standard template exists, including international transfer safeguards.
Terms & Conditions
Public — no NDA required
Privacy Policy
Public — no NDA required
Cookies Policy
Public — no NDA required
Third parties that may process customer data on our behalf. Each is assessed under our Vendor Management Procedure before onboarding and reviewed periodically. We notify customers in advance of material changes — email we@holisticai.com to be added to that list.
Amazon Web Services · Cloud infrastructure and data hosting
Hosting, backup and disaster recovery for the Holistic AI platform. Europe (London) is the default region; US customers are hosted in US East (Ohio).
UK · US
Google Cloud Platform · Cloud infrastructure and data hosting
Alternative hosting for US customers where required in place of AWS.
US
WorkOS · Authentication and user management
Sign-in, single sign-on and user directory management for the platform.
US
Twilio SendGrid · Transactional email
Service notifications and account messages sent from the platform.
US
Locations shown are the jurisdictions in which each provider operates for Holistic AI. Transfers outside the UK and EEA are covered by the transfer safeguards in our standard Data Processing Agreement, available under NDA.
If your question is not here, ask us directly.
Request access and tell us your name, company and which documents you need. We send our standard mutual NDA for e-signature, or use the one already in place with your company. Access is granted within two business days, usually the same day.
Our audit reports and policies describe how we secure our systems in detail. That detail is useful to a customer assessing us and equally useful to an attacker, so we share it under a mutual NDA rather than publishing it openly.
Yes. Send it to we@holisticai.com. Reviewing our SOC 2 report and ISO 27001 documentation first will usually answer most of it.
The information security management system supporting the development and deployment of the Holistic AI platform, covering our Engineering, IT, HR, Admin, Customer Support, Sales and Marketing functions. A certification is only as meaningful as its scope, so the full scope statement and Statement of Applicability are both available under NDA.
Certification runs on a three-year cycle with annual surveillance audits by our certification body in between, and we run our own internal ISMS audit and management review at least annually. Certification is a point in time; the surveillance cycle is what keeps it honest.
Annually, by an independent third party. The executive summary is available under NDA — request it alongside our audit reports.
Not yet. Our ISO/IEC 42001 certification audit is scheduled for the coming months and we will update this page when it completes. We would rather tell you where we actually are than imply a certificate we do not hold.
Email we@holisticai.com with enough detail for us to reproduce it. We acknowledge every report and keep you updated until it is resolved. Please do not access data that is not yours, and do not degrade the service for others while testing.
No. We do not use customer data to train models.
We do not build or train models of our own. The Holistic AI platform assesses and governs the AI systems our customers build or buy — it does not learn from the data it handles. Your data is used only to run the service for you.
Within 72 hours of a confirmed incident affecting your data, or within the timeline agreed in your MSA if that is shorter. Notification runs under our Incident Management Procedure and Personal Data Breach Notification Policy.
By default, in the UK — Amazon Web Services, Europe (London). US customers are hosted in the United States: AWS US East (Ohio), or Google Cloud Platform where required. Data is replicated across multiple regions for redundancy and disaster recovery.
Yes. A standard Data Processing Agreement template exists, including international transfer safeguards, available on request.
Holistic AI Limited is the data controller where customers provide personal data directly through the Website. In such circumstances, the Information Commissioner’s Office (ICO) is our supervisory authority.
Where we enter into an MSA with a customer, Holistic AI Limited acts as a data processor and processes personal data solely on the customer’s documented instructions, in accordance with the applicable data protection provisions in the MSA and, where required, a Data Processing Agreement (DPA). Our processing activities are therefore undertaken in accordance with the UK GDPR and the Data Protection Act 2018, as applicable to our role as either controller or processor.
Data is retained only as long as necessary for the purpose it was collected for, or according to the timeline set out in your MSA. Deletion is initiated on termination or on your request; your data is then permanently removed from storage, databases and backups using our secure deletion protocols. Written confirmation of deletion is available on request.
Changes to our certifications, documents and subprocessor list. Newest first.
Subprocessors
August 2026
We now publish our full subprocessor list, with the purpose and operating jurisdiction of each. Email us to be added to the advance notification list for changes.
Compliance
August 2026
We will undergo an ISO/IEC 42001 audit for our AI management system in the coming months. We are not certified today; this page will be updated when the audit completes.
Compliance
February 2026
Our information security management system was certified against ISO/IEC 27001:2022 following a Stage 2 audit by our certification body, with no nonconformities raised. The certificate, the audit report and the Statement of Applicability are available under NDA.
Compliance
April 2025
Our SOC 2 Type 2 report covering Security, Availability, Confidentiality and Privacy is available to customers and prospects under NDA.
Join the organizations that turned governance from a blocker into an enabler. Full visibility, continuous risk testing, and compliance proof — on autopilot.
Get a Demo
Recognized by




