Trust Built Into Every Layer
CSOAI is built on security, transparency, and compliance. Our controls are described honestly — what is attained is marked attained, what is in progress is marked in progress, and we do not claim audits we have not undergone.
From encryption to incident response, from ISO certifications to compliance frameworks—we take security seriously so you don't have to.
Certification Status, Marked Honestly
Frameworks below are marked “In Progress” because they are genuinely in progress. Nothing on this page is claimed as attained until an assessor’s letter exists — and when one does, it will be published here.
ISO 27001
Information Security Management System
ISO 42001
AI Management System
SOC 2 Type II
Security, Availability, and Confidentiality
GDPR Compliant
European Data Protection Regulation
Enterprise-Grade Data Protection
Your data is protected with industry-standard encryption (AES-256 at rest, TLS 1.3 in transit) and compliance with global data protection regulations.
Encryption at Rest
AES-256 encryption for all data stored in databases and file systems
Encryption in Transit
TLS 1.3 for all data transmitted between clients and servers
Data Residency
Site served from Cloudflare's global edge network; the measurement backend is first-party, self-hosted UK/EU. Per-region residency selection is designed, not yet offered
Data Retention
Configurable retention policies with automatic deletion after specified periods
Right to Erasure
Full compliance with GDPR Article 17 - instant data deletion upon request
Access Controls
Role-based access control (RBAC) with MFA and audit logging
Data Residency — Current Status
The public site is served from Cloudflare’s global edge network; the measurement backend (os.meok.ai) runs on first-party infrastructure in the UK/EU. A per-region residency choice (EU / US / APAC) is designed but not yet offered — this card will name regions and safeguards on the day it ships, not before.
Infrastructure Security
Multi-layered security architecture protecting against evolving threats.
Cloud Infrastructure
Static-first deployment on Cloudflare's global edge network, with always-free Oracle nodes for measurement workloads
DDoS Protection
DDoS mitigation via Cloudflare's network layer
Web Application Firewall
Network-layer filtering via Cloudflare on all public endpoints
Penetration Testing
No third-party penetration test has been performed yet. When one exists, its letter will be published in the Security Pack below
Bug Bounty Program
No paid bug-bounty programme exists today. We run a published vulnerability disclosure policy instead
Incident Response
Incident response follows the published protocol below and the honest incident log on /status. There is no staffed 24/7 security operations center today
Aligned With Global Frameworks
CSOAI is designed with compliance for international AI governance frameworks built in from the ground up.
EU AI Act
Full compliance with risk-based regulation of AI systems
NIST AI Risk Management Framework
Governance, measurement, and control aligned with NIST RMF 1.0
OECD AI Principles
Inclusive growth, sustainable development, and well-being oriented
UNESCO AI Recommendation
Human-centered and human-supervised AI systems
Privacy & Data Management
Complete transparency and control over your data with accessible policies and agreements.
Privacy Policy
Transparent privacy policy outlining data collection, use, and retention practices
Cookie Policy
Clear cookie disclosure with user-controlled consent management
Data Processing Agreements
Standard DPA templates available for enterprise customers (GDPR Article 28)
Sub-processor List
Complete list of third-party data processors with links to their privacy policies
Who Processes Your Data
Every third party that touches data on our behalf, named. If a vendor is not on this list, it does not process your data. We notify customers before adding any new processor.
| Vendor | Purpose | Data categories | Location | Safeguard |
|---|---|---|---|---|
| Cloudflare | Hosting, edge network, DNS and DDoS protection for csoai.org | Site traffic logs, IP addresses, cached page content | Global edge network (US/EU) | Cloudflare DPA; SCCs / UK IDTA for international transfers |
| Stripe | Payment processing | Billing name, email and payment metadata — card numbers never touch our servers | United States / Ireland | Stripe DPA; SCCs / UK IDTA |
| Vercel | Legacy hosting — being retired | Historical deployment and access logs only | United States | Vercel DPA; SCCs / UK IDTA |
| GitHub | Source code hosting and CI | Code, issues and contributor metadata; no production personal data | United States | GitHub DPA; SCCs / UK IDTA |
| Hugging Face | Hosting of public datasets and models | Public, non-personal datasets only | United States | Public data only — no personal data is processed |
| os.meok.ai (first-party) | Sovereign inference and governance gateway | Governance and inference requests | Self-hosted, UK/EU | First-party infrastructure — not a subprocessor; listed for transparency |
| Email provider | Support and transactional email | Contact details and correspondence | See DPA | Confirmed in the Data Processing Agreement |
Questions about a specific vendor, or need this register as part of an executed DPA? [email protected]
What’s Public Today vs What’s Shared Under NDA
Everything in the first column is a real artifact you can open right now. Everything in the second column exists only where we say it does — and is shared under NDA on request. We do not list pen-test letters or certificates we cannot show you.
Public today
Shared under NDA
Request NDA materials via [email protected]
Monitoring & Incident Response
The figures below are design targets, marked as such. Live component status and the honest incident log are public at csoai.org/status.
Response SLA
Monitoring — designed
Automated health probes run against the public status page; no staffed 24/7 operations center exists today
Detection — target 15 min
Design target for detecting a probe failure — not yet a measured figure
Containment — target 1 hour
Design target to contain and isolate affected systems — not yet a measured figure
Availability
24-Hour Notification
Maximum time to notify affected users of security incidents
Uptime
Not measured publicly — see /status for live availability of probed services
Incident Communication Protocol
Detection
Automated probes surface failures on /status
Verification
Confirm incident and assess impact
Notification
Notify affected users within 24 hours
Resolution
Root cause analysis within 72 hours
Security FAQ
Answers to common questions about CSOAI's security and compliance practices.
What encryption standards do you use?
What compliance certifications do you have?
Where is my data stored?
What is your incident response process?
How often do you conduct security assessments?
Can you permanently delete my data?
Who are your sub-processors?
What is your uptime guarantee?
Security & Compliance Inquiries
Have questions about our security practices, certifications, or compliance? Our security team is ready to help.
Security Report
Responsible disclosure of security vulnerabilities:
Follow our responsible disclosure policyPrivacy Questions
Ready to Build With Confidence?
Deploy AI systems on a platform designed with security and compliance from day one.
Trust posture, measured
source: /status page + subprocessor register, 2026-08-01
Frequently asked questions
How this site is actually run — the honest posture, not the brochure one.
Where is CSOAI infrastructure hosted?
The public site is served from Cloudflare's edge network; measurement services run on a small sovereign fleet (Oracle Cloud and self-hosted nodes). We publish the real posture — no borrowed multi-region claims.
Is there a real status page?
Yes. /status distinguishes live-probed rows from surfaces not probed from that page, and keeps a public incident log — including our own deploy regression of 31 July 2026, resolved in 45 minutes and published.
Who are your subprocessors?
A named subprocessor register is published on the trust centre — the actual vendors we use, not a generic list. Changes are announced before they take effect where feasible.
Have you been independently audited or pen-tested?
We do not claim audits we cannot produce. What exists today: continuous self-measurement published as signed artefacts, a public refutation ledger, and a vulnerability-disclosure channel. When an independent artefact exists, it will be linked here.
Last updated: July 2026. For the most current security and certification status, please contact [email protected]. Certifications marked “In Progress” are being pursued; where a certification is held, it is verified by an accredited third-party auditor.