Security & Compliance
We design every deployment so your IT team can verify it and your auditors can follow it.
Principles
- Least privilege: people and systems get only the access they need.
- Data minimisation: AI receives only the data a task requires.
- Defence in depth: network, identity, application and logging controls, each on its own.
- You own it: your keys, your logs, your data, your documentation.
- Written down: every control is documented, not just configured.
Standards we align with
| Framework | What we do |
|---|---|
| ISO/IEC 27001 | We map each deployment’s controls to Annex A and provide the evidence documentation your ISMS needs. |
| GDPR | We document data flows and processing, support your DPIA where processing is high-risk, and keep data in the EU where required. |
| EU AI Act | We help you classify each use case and document the transparency and oversight measures it needs. |
| NIS2 | If your organisation falls under NIS2, we work to your supplier security requirements. |
What we do not claim
We are not a certification body and we do not certify your organisation. Certification under ISO/IEC 27001 is granted to an organisation by an accredited auditor. What we provide is systems and documentation designed to make that audit easier. For legal interpretation, we work alongside your lawyer or data protection officer.
Report a vulnerability
If you believe you have found a security issue on this website, please tell us privately at contact@plugtrustai.com, with “Security” in the subject.
- Include: the page or address, the steps to reproduce, and the impact you expect.
- Please do not: access or change data that is not yours, run denial-of-service tests, or use social engineering.
- Our commitment: we acknowledge reports within 5 working days, keep you updated, and credit you if you wish once the issue is fixed.
- Good faith: we will not take legal action against research carried out in good faith and in line with this policy.
Please give us reasonable time to fix an issue, normally up to 90 days, before you disclose it publicly. We do not run a paid bug bounty.