Skip to main content

Security & Compliance

Governed private AI with reviewable evidence at every layer

Review the controls that protect private AI today, alongside dated evidence and an explicit certification roadmap.

Where we stand today

  • Architecture-level security in place — encryption, RBAC, SSO, audit
  • ISO 27001 + SOC 2 Type II on active roadmap
  • ISO 42001 (AI lifecycle and governance) planned after ISO 27001

Certifications roadmap

Clear about certification status and review evidence.

We will not list certifications we do not hold. The platform is built with enterprise controls now; formal audits follow the company roadmap and customer procurement requirements.

Architecture-level security

What's in place today, not on a roadmap.

These are the controls customers can review and validate during procurement — independent of certification status.

AI-specific protections

Controls designed for AI threat models, not just web app risk.

Generic enterprise security is necessary but not sufficient for AI workloads. These controls are designed specifically for the AI attack surface.

  1. 01

    Prompt injection defenses

    Multi-layered detection at gateway and model layer — configurable filtering and policy enforcement before model invocation. Addresses OWASP LLM Top 10 #1 risk for enterprise deployments.

  2. 02

    Output filtering

    Customer-defined content policy enforcement, topic restrictions, and output guardrails — applied before every response. Your security team sets the rules; Iftah enforces them.

  3. 03

    Configurable model output logging

    Full trace, redacted trace, sampled trace, or metadata-only mode — you choose what is logged and where it lives. The resulting trail supports access, accountability, and incident-review requirements.

  4. 04

    Data poisoning detection

    Validation pipelines for fine-tuning datasets, anomaly detection, and provenance tracking — keeps your model integrity inside your perimeter.

Procurement

How our security review works in procurement.

We invite your security team to review before you sign — not after.

  1. 01

    Week 1–2

    Architecture review

    We provide a network diagram, data-flow document, threat model, and deployment architecture for your security team to review before any procurement decision.

  2. 02

    Week 2–4

    Penetration testing

    You can conduct your own penetration test against a staging deployment in a dedicated environment. No NDA clause preventing you from using findings in your procurement process.

  3. 03

    Week 4–6

    Control validation

    Your security reviewers validate our control claims against spec — encryption standards, access logs, audit trail, network isolation. We provide the evidence; you verify it.

For your CISO

What your CISO will want to know about AI-specific risk.

Output filtering and content policy enforcement are applied before every response. Customer-defined rules. Logs of filtered content retained in your environment, not ours.
Multi-layer detection at both the gateway and model layer. Sanitisation and policy enforcement run before model invocation — not as a post-hoc filter that can be bypassed.
Full trace mode: every prompt, response, token count, latency, model version, identity, and policy outcome logged in your environment. You choose the logging mode and retention policy — we have no access to the logs.
Iftah CGM is default-deny on every agent call. No agent acts without an explicit, logged policy allow. Unauthorised attempts are logged with full context — identity, requested action, denial reason, and timestamp.

Regulatory control mapping

Architecture designed to support the regulations you're accountable to.

We do not claim certified compliance with customer-specific regimes — compliance remains the data controller's obligation. The deployment model gives customers controls and evidence for applicable privacy, cybersecurity, data-residency, and financial-sector reviews.

Review regulatory mappingمراجعة تخطيط الضوابط التنظيمية

Data residency controls

Customer-selected region and provider. You control what data exits the perimeter — all exports require explicit customer approval.

Audit-ready logging

Requests, policy decisions, model actions, and admin events are logged with timestamp, identity, and policy outcome.

Access governance

Identity-bound permissions, service account isolation, and reviewable access patterns mapped to regulator expectations.

Next step

Review Iftah AI against your environment before choosing the first workload.