Trust, security and responsible AI

We design and operate our AI platforms to meet the security, privacy and governance expectations of UK public sector organisations. Transparency, accountability and responsible AI use are central to how our platform is built and operated.

Used in live public services supporting residents across health, care and local services.

Responsible AI & governance

Our platform is designed to support safe, appropriate and accountable use of AI in public-facing services.

  • Closed knowledge system
    AI assistants are restricted to using approved, pre-defined council content and documentation only.
  • No training on user data
    Resident interactions are not used to train AI models.
  • Human-in-the-loop oversight
    Safeguarding, escalation and review processes are built into the platform.
  • Controlled AI behaviour
    AI is constrained to information provision and guidance – not autonomous decision-making.
  • Transparency by design
    Clear explanations of what the AI can and cannot do.

Data protection & privacy

We apply strong technical and organisational measures to protect information throughout its lifecycle.

  • Data minimisation principles applied by default
  • Personal data avoided wherever possible
  • Encryption in transit and at rest
  • Logical separation between council deployments
  • Alignment with UK GDPR and public-sector data protection expectations
  • DPIA-first deployment approach

Infrastructure & operational security

Our platform is operated using secure, modern infrastructure and established security practices.

  • Secure cloud hosting environment
  • Role-based access control (RBAC)
  • Regular patching and security updates
  • Monitoring and alerting for abnormal behaviour
  • Incident response processes in place
  • Regular security reviews and vulnerability testing

Procurement & frameworks

Our accreditation status helps councils engage with us confidently and efficiently, reducing procurement friction.

G-Cloud 15 (Crown Commercial Supplier)

We are an approved supplier on the G-Cloud 15 framework, enabling central government, local authorities and public-sector organisations to procure our services through a compliant and well-understood route – without the need for lengthy full tendering processes.


Security certifications & standards

We maintain recognised certifications and management systems to support security, quality and responsible AI governance.

Cyber Essentials Plus

We are Cyber Essentials Plus certified, providing independent assurance that our security controls have been externally tested and verified.

Cyber Essentials Plus goes beyond self-assessment and includes hands-on technical validation by an accredited assessor. This demonstrates that we have effective controls in place to protect systems and data against common cyber threats.

Cyber Essentials Plus provides assurance that we:

  • Protect against common attack vectors
  • Maintain secure system configuration
  • Control and restrict access to data and services
  • Apply effective patching and malware protection
  • Have security controls that have been independently tested

This level of certification is widely recognised and trusted across UK public-sector organisations.


ISO/IEC 27001:2022

We are certified to ISO/IEC 27001:2022, the international standard for information security management systems, certified by Citation ISO Certification Limited.

The scope of our certification covers the provision of technical consultancy and development for web-based solutions, including AI-driven digital assistants, to public and private sector organisations.

ISO/IEC 27001 provides independent assurance that we:

  • Systematically identify and manage information security risks
  • Maintain robust access control, encryption and data handling practices
  • Operate a continual improvement cycle for our security management system
  • Are independently audited on an ongoing basis to retain certification
  • This certification underpins the technical and organisational measures described elsewhere on this page.

ISO/IEC 42001:2023

We are certified to ISO/IEC 42001, the international standard for AI Management Systems.

This certification demonstrates that we have formal governance in place for the responsible development, deployment and operation of AI systems, including:

  • AI risk assessment and mitigation
  • Human oversight and accountability
  • Transparency and explainability
  • Ongoing monitoring and continuous improvement

ISO/IEC 42001 provides independent assurance that AI risks are actively managed — particularly important for public-sector use cases.


ISO 9001

We operate a Quality Management System aligned with ISO 9001.

This ensures that our internal processes support:

  • Consistent service delivery
  • Clear documentation and accountability
  • Continuous improvement
  • Customer and stakeholder focus

ISO 9001 underpins how we design, deliver and support our platform for public-sector clients.


Simplifying Governance for Councils

We have specifically designed our products to minimise IG complexity for your organisation.

No personal data in AI

For solutions like Aida, the AI model does not process or store personal data within the conversation, significantly simplifying your IG requirements.

Standalone tool

Our assistants are built to be standalone tools, isolating user interaction data securely within our UK-hosted platform and preventing data overlap with your existing, often complex, systems.

UK GDPR Compliance

Our commitment to processing data strictly in accordance with UK GDPR is fundamental to our service. We ensure full transparency, strong security measures, and robust procedures for data handling, giving you complete assurance over citizen and service data.

Ready to see the future of public service?

Get access to a demo to experience our secure AI solutions. You’ll get to see exactly how they work and choose which product you’d like to dive into.