Security & Compliance

Trust Built Into Every Layer

CSOAI is built on security, transparency, and compliance. Our controls are described honestly — what is attained is marked attained, what is in progress is marked in progress, and we do not claim audits we have not undergone.

From encryption to incident response, from ISO certifications to compliance frameworks—we take security seriously so you don't have to.

Certifications

Certification Status, Marked Honestly

Frameworks below are marked “In Progress” because they are genuinely in progress. Nothing on this page is claimed as attained until an assessor’s letter exists — and when one does, it will be published here.

In Progress

ISO 27001

Information Security Management System

In Progress

ISO 42001

AI Management System

In Progress

SOC 2 Type II

Security, Availability, and Confidentiality

Compliant

GDPR Compliant

European Data Protection Regulation

Data Protection

Enterprise-Grade Data Protection

Your data is protected with industry-standard encryption (AES-256 at rest, TLS 1.3 in transit) and compliance with global data protection regulations.

Encryption at Rest

AES-256 encryption for all data stored in databases and file systems

Encryption in Transit

TLS 1.3 for all data transmitted between clients and servers

Data Residency

Site served from Cloudflare's global edge network; the measurement backend is first-party, self-hosted UK/EU. Per-region residency selection is designed, not yet offered

Data Retention

Configurable retention policies with automatic deletion after specified periods

Right to Erasure

Full compliance with GDPR Article 17 - instant data deletion upon request

Access Controls

Role-based access control (RBAC) with MFA and audit logging

Data Residency — Current Status

The public site is served from Cloudflare’s global edge network; the measurement backend (os.meok.ai) runs on first-party infrastructure in the UK/EU. A per-region residency choice (EU / US / APAC) is designed but not yet offered — this card will name regions and safeguards on the day it ships, not before.

Infrastructure

Infrastructure Security

Multi-layered security architecture protecting against evolving threats.

Cloud Infrastructure

Static-first deployment on Cloudflare's global edge network, with always-free Oracle nodes for measurement workloads

Edge-cached worldwide
Signed artefacts
Fail-closed measurement

DDoS Protection

DDoS mitigation via Cloudflare's network layer

Automatic traffic filtering
Layer 3-7 protection
24/7 monitoring

Web Application Firewall

Network-layer filtering via Cloudflare on all public endpoints

Managed rules
Rate limiting
DDoS mitigation

Penetration Testing

No third-party penetration test has been performed yet. When one exists, its letter will be published in the Security Pack below

Planned, not performed
Letter will be published
No fake claims

Bug Bounty Program

No paid bug-bounty programme exists today. We run a published vulnerability disclosure policy instead

Responsible disclosure
security.txt (RFC 9116)
Coordinated timelines

Incident Response

Incident response follows the published protocol below and the honest incident log on /status. There is no staffed 24/7 security operations center today

Published protocol
Public incident log
Root cause analysis
Global Compliance

Aligned With Global Frameworks

CSOAI is designed with compliance for international AI governance frameworks built in from the ground up.

EU AI Act

In Scope

Full compliance with risk-based regulation of AI systems

NIST AI Risk Management Framework

Aligned

Governance, measurement, and control aligned with NIST RMF 1.0

OECD AI Principles

Aligned

Inclusive growth, sustainable development, and well-being oriented

UNESCO AI Recommendation

Aligned

Human-centered and human-supervised AI systems

Privacy

Privacy & Data Management

Complete transparency and control over your data with accessible policies and agreements.

Privacy Policy

Transparent privacy policy outlining data collection, use, and retention practices

Cookie Policy

Clear cookie disclosure with user-controlled consent management

Data Processing Agreements

Standard DPA templates available for enterprise customers (GDPR Article 28)

Sub-processor List

Complete list of third-party data processors with links to their privacy policies

Important Links

Subprocessors

Who Processes Your Data

Every third party that touches data on our behalf, named. If a vendor is not on this list, it does not process your data. We notify customers before adding any new processor.

VendorPurposeData categoriesLocationSafeguard
CloudflareHosting, edge network, DNS and DDoS protection for csoai.orgSite traffic logs, IP addresses, cached page contentGlobal edge network (US/EU)Cloudflare DPA; SCCs / UK IDTA for international transfers
StripePayment processingBilling name, email and payment metadata — card numbers never touch our serversUnited States / IrelandStripe DPA; SCCs / UK IDTA
VercelLegacy hosting — being retiredHistorical deployment and access logs onlyUnited StatesVercel DPA; SCCs / UK IDTA
GitHubSource code hosting and CICode, issues and contributor metadata; no production personal dataUnited StatesGitHub DPA; SCCs / UK IDTA
Hugging FaceHosting of public datasets and modelsPublic, non-personal datasets onlyUnited StatesPublic data only — no personal data is processed
os.meok.ai (first-party)Sovereign inference and governance gatewayGovernance and inference requestsSelf-hosted, UK/EUFirst-party infrastructure — not a subprocessor; listed for transparency
Email providerSupport and transactional emailContact details and correspondenceSee DPAConfirmed in the Data Processing Agreement

Questions about a specific vendor, or need this register as part of an executed DPA? [email protected]

Security Pack

What’s Public Today vs What’s Shared Under NDA

Everything in the first column is a real artifact you can open right now. Everything in the second column exists only where we say it does — and is shared under NDA on request. We do not list pen-test letters or certificates we cannot show you.

Shared under NDA

Executed DPA with customer-specific annexes
Infrastructure architecture diagrams and data-flow maps
Incident response runbook (current revision)
Penetration-test summaries and audit letters — none are claimed today; when an assessment exists, its letter will be listed here

Request NDA materials via [email protected]

Operations

Monitoring & Incident Response

The figures below are design targets, marked as such. Live component status and the honest incident log are public at csoai.org/status.

Response SLA

Monitoring — designed

Automated health probes run against the public status page; no staffed 24/7 operations center exists today

Detection — target 15 min

Design target for detecting a probe failure — not yet a measured figure

Containment — target 1 hour

Design target to contain and isolate affected systems — not yet a measured figure

Availability

24-Hour Notification

Maximum time to notify affected users of security incidents

Uptime

Not measured publicly — see /status for live availability of probed services

Incident Communication Protocol

1

Detection

Automated probes surface failures on /status

2

Verification

Confirm incident and assess impact

3

Notification

Notify affected users within 24 hours

4

Resolution

Root cause analysis within 72 hours

Common Questions

Security FAQ

Answers to common questions about CSOAI's security and compliance practices.

What encryption standards do you use?

What compliance certifications do you have?

Where is my data stored?

What is your incident response process?

How often do you conduct security assessments?

Can you permanently delete my data?

Who are your sub-processors?

What is your uptime guarantee?

Get in Touch

Security & Compliance Inquiries

Have questions about our security practices, certifications, or compliance? Our security team is ready to help.

Email Us

For detailed security questions and certification inquiries:

[email protected]

Security Report

Responsible disclosure of security vulnerabilities:

Follow our responsible disclosure policy

Privacy Questions

Data Privacy Requests

GDPR data access, deletion, or portability requests

[email protected]

DPA & Compliance

Data Processing Agreements and compliance documentation

[email protected]

Ready to Build With Confidence?

Deploy AI systems on a platform designed with security and compliance from day one.

Trust posture, measured

1
published incident with full timeline (31 Jul 2026 deploy regression, 45-min resolution)
measured
100%
status rows labelled live-probed vs not-probed — no implied coverage
measured
0
independent audits claimed without an artefact
measured

source: /status page + subprocessor register, 2026-08-01

FAQs

Frequently asked questions

How this site is actually run — the honest posture, not the brochure one.

Where is CSOAI infrastructure hosted?

The public site is served from Cloudflare's edge network; measurement services run on a small sovereign fleet (Oracle Cloud and self-hosted nodes). We publish the real posture — no borrowed multi-region claims.

Is there a real status page?

Yes. /status distinguishes live-probed rows from surfaces not probed from that page, and keeps a public incident log — including our own deploy regression of 31 July 2026, resolved in 45 minutes and published.

Who are your subprocessors?

A named subprocessor register is published on the trust centre — the actual vendors we use, not a generic list. Changes are announced before they take effect where feasible.

Have you been independently audited or pen-tested?

We do not claim audits we cannot produce. What exists today: continuous self-measurement published as signed artefacts, a public refutation ledger, and a vulnerability-disclosure channel. When an independent artefact exists, it will be linked here.

Last updated: July 2026. For the most current security and certification status, please contact [email protected]. Certifications marked “In Progress” are being pursued; where a certification is held, it is verified by an accredited third-party auditor.