Principles

  • Least privilege: people and systems get only the access they need.
  • Data minimisation: AI receives only the data a task requires.
  • Defence in depth: network, identity, application and logging controls, each on its own.
  • You own it: your keys, your logs, your data, your documentation.
  • Written down: every control is documented, not just configured.

Standards we align with

FrameworkWhat we do
ISO/IEC 27001We map each deployment’s controls to Annex A and provide the evidence documentation your ISMS needs.
GDPRWe document data flows and processing, support your DPIA where processing is high-risk, and keep data in the EU where required.
EU AI ActWe help you classify each use case and document the transparency and oversight measures it needs.
NIS2If your organisation falls under NIS2, we work to your supplier security requirements.

What we do not claim

We are not a certification body and we do not certify your organisation. Certification under ISO/IEC 27001 is granted to an organisation by an accredited auditor. What we provide is systems and documentation designed to make that audit easier. For legal interpretation, we work alongside your lawyer or data protection officer.

Report a vulnerability

If you believe you have found a security issue on this website, please tell us privately at contact@plugtrustai.com, with “Security” in the subject.

  • Include: the page or address, the steps to reproduce, and the impact you expect.
  • Please do not: access or change data that is not yours, run denial-of-service tests, or use social engineering.
  • Our commitment: we acknowledge reports within 5 working days, keep you updated, and credit you if you wish once the issue is fixed.
  • Good faith: we will not take legal action against research carried out in good faith and in line with this policy.

Please give us reasonable time to fix an issue, normally up to 90 days, before you disclose it publicly. We do not run a paid bug bounty.