Skip to main content

Security & Compliance

Governed private AI with reviewable evidence at every layer

Evaluate platform security controls, dated evidence, and certification progress to support your deployment review.

Current Security and Assurance Status

  • Architecture-level security in place — encryption, RBAC, SSO, audit
  • ISO 27001 + SOC 2 Type II on active roadmap
  • ISO 42001 (AI lifecycle and governance) planned after ISO 27001

Certifications roadmap

Certification Status and Review Evidence

Review current enterprise controls alongside the status, scope, and target dates for each certification program. Planned certifications are identified separately from completed assessments.

Certification program in progress. Target: Q4 2026. Last reviewed: 21 August 2026. Evidence available: Control mapping and architecture review materials.

Assurance program in progress. Target: H1 2027. Last reviewed: 21 August 2026. Evidence available: Control mapping and customer-led review materials.

Planned. Target: After ISO/IEC 27001. Scope: AI lifecycle, model governance, and accountability. No certification evidence published.

Available at procurement — before contract signature. Security architecture, network diagram, threat model, and deployment documentation provided for your team to review and test.

Architecture-level security

Security Controls Available for Review

Validate these platform controls during procurement, alongside the documented certification status.

Spec
AES-256 / TLS 1.3
Evidence
AES-256 at rest. TLS 1.3 in transit. Standard cryptographic patterns inside the customer's environment.

Spec
RBAC + SSO
Evidence
Role-based access with fine-grained permissions. SSO via SAML 2.0 and OIDC. Customer-owned identity provider.

Spec
Every action
Evidence
Every request, policy decision, model action, and admin event audit-logged. Prompt and response content follows the trace mode your team approves.

Spec
Standard K8s
Evidence
Namespace isolation, secrets management, network policies (ingress/egress), and air-gapped cluster support via standard Kubernetes.

Spec
Per-agent identity binding, WORM audit
Evidence
Bind AI agent calls to signed identities and require an explicit, logged policy approval before execution.

AI-specific protections

Protection Designed for AI Workloads

Extend enterprise security with controls for prompt injection, model outputs, data integrity, and AI activity logging.

  1. 01

    Prompt injection defenses

    Multi-layered detection at gateway and model layer — configurable filtering and policy enforcement before model invocation. Addresses OWASP LLM Top 10 #1 risk for enterprise deployments.

  2. 02

    Output filtering

    Customer-defined content policy enforcement, topic restrictions, and output guardrails — applied before every response. Your security team sets the rules; Iftah enforces them.

  3. 03

    Configurable model output logging

    Full trace, redacted trace, sampled trace, or metadata-only mode — you choose what is logged and where it lives. The resulting trail supports access, accountability, and incident-review requirements.

  4. 04

    Data poisoning detection

    Validation pipelines for fine-tuning datasets, anomaly detection, and provenance tracking — keeps your model integrity inside your perimeter.

Procurement

A Structured Security Review for Procurement

Evaluate security architecture, controls, and evidence with your team before contracting.

  1. 01

    Week 1–2

    Architecture review

    We provide a network diagram, data-flow document, threat model, and deployment architecture for your security team to review before any procurement decision.

  2. 02

    Week 2–4

    Penetration testing

    You can conduct your own penetration test against a staging deployment in a dedicated environment. No NDA clause preventing you from using findings in your procurement process.

  3. 03

    Week 4–6

    Control validation

    Your security reviewers validate our control claims against spec — encryption standards, access logs, audit trail, network isolation. We provide the evidence; you verify it.

For your CISO

Key Questions for Your AI Security Review

Apply output filtering and customer-defined content policies before responses are returned. Retain review logs in your environment under your access and retention policies.

Gateway and model-layer detection, sanitization, and policy enforcement evaluate requests before model invocation. Configure these controls for your workloads and review the resulting decisions.

Full trace mode records prompts, responses, token counts, latency, model versions, identities, and policy outcomes in your environment. Your team sets the logging mode, retention policy, and access permissions.

Iftah CGM requires explicit policy approval for agent calls. Unauthorized attempts are blocked and logged with the identity, requested action, denial reason, and timestamp.

Regulatory control mapping

Map Platform Controls to Your Regulatory Requirements

Map deployment controls and evidence to applicable privacy, cybersecurity, data-residency, and financial-sector requirements. Your organization retains responsibility for its compliance assessments and obligations; platform controls support that review rather than certify compliance.

Review regulatory mappingمراجعة تخطيط الضوابط التنظيمية

Data residency controls

Customer-selected region and provider. You control what data exits the perimeter — all exports require explicit customer approval.

Audit-ready logging

Requests, policy decisions, model actions, and admin events are logged with timestamp, identity, and policy outcome.

Access governance

Identity-bound permissions, service account isolation, and reviewable access patterns mapped to regulator expectations.

Next step

Review Iftah AI against your environment before choosing the first workload.