Skip to main content
NEW GUIDEFour ways to make a regulated firm AI-nativeGet the deck
Softblues

Security & trust

How does Softblues approach AI security and data protection?

Security starts with the task, the information involved and the systems it touches. We work with your team to define access, data flows, permitted actions and operational responsibilities for the engagement. Controls depend on the chosen platform and implementation, and are agreed as part of the scope.

  • OpenAI Select Partner
  • Google Cloud Services Partner
  • Claude Partner Network Certified
  • Member of the Microsoft AI Cloud Partner Program

What controls do we scope with you?

Six areas, agreed with your team rather than assumed. What is available in each depends on the chosen platform and implementation.

  • Access and permissions

    Define the users, service identities and connectors involved, with the permissions required for their tasks and an owner for access changes.

  • Data handling

    Identify sources, destinations, model providers, logs and retention requirements. Review the relevant provider settings and contractual terms for the selected services.

  • Action boundaries

    Specify what an assistant or agent may do, which actions require approval and how it should handle a request outside its scope.

  • Testing and evaluation

    Agree representative tests, failure cases and security checks appropriate to the application before launch.

  • Logging and monitoring

    Specify which events are recorded, who may inspect them, how long they are retained and who responds to an alert. Logging coverage varies by platform and implementation.

  • Handover and operation

    Document ownership, support responsibilities, access removal and the process for making changes after delivery.

Where will data be stored and processed?

The answer depends on the deployment, platform, model endpoint and connected services. An application hosted in your cloud account can still send information to a model provider or another service. Storage location, processing location and retention need to be examined separately.

During scoping, we identify the relevant data flows and requirements with your IT or security team. Provider documentation and the terms for the selected service determine which controls are available.

A provider’s certification does not certify Softblues or your complete solution.

What should a security review cover?

Six areas to establish before access or implementation begins. Use it to prepare your own review rather than as evidence that one has been passed.

Areas a security review should establish
AreaWhat to establish
InformationData categories, approved sources and sensitive fields
AccessAuthorised people, service identities and permissions
ProvidersSelected services, processing locations and applicable terms
ActionsAllowed operations, approval points and exception handling
EvidenceTest scope, logging coverage and access to records
OperationRetention, change control, support and incident responsibilities

Send the requirements or questionnaire you need us to address. We will identify the relevant scope, available documentation and any gaps to resolve.

Do not include credentials or sensitive records in the initial contact form.

What is Softblues' certification status?

Softblues is not ISO 27001 certified. Our security approach is informed by ISO 27001 principles, with the controls and responsibilities for an engagement defined during scoping.

Certification claims for any hosting or model provider should be checked separately against the actual service being used.

What has this looked like in an audit?

An anonymised AI-built application audit identified a storage-access exposure before go-live. The urgent exposure was closed and the wider rebuild was proposed separately. It illustrates why access must be checked at the service and data layers, as well as in the interface.

Stage: audit delivered; rebuild proposed. It is one engagement, not evidence about every build.

Key facts

Security and trust: at a glance

Certification
Softblues is not ISO 27001 certified. The approach is informed by ISO 27001 principles, with controls and responsibilities defined during scoping.
What we scope
Access and permissions, data handling, action boundaries, testing and evaluation, logging and monitoring, and handover and operation.
Storage and processing
Depends on the deployment, platform, model endpoint and connected services. Storage location, processing location and retention are examined separately.
Logging
Which events are recorded, who may inspect them, how long they are retained and who responds to an alert are agreed. Coverage varies by platform and implementation.
Model training
Checked against the specific provider, product, account settings and agreed data use. Any project-specific fine-tuning would be explicitly scoped and agreed.
Provider certifications
A provider's certification does not certify Softblues or your complete solution. Check it against the actual service being used.
Compliance
We assess your requirements against the proposed implementation. The project scope cannot replace your organisation’s legal, compliance or security approval.

Common questions about security

Is Softblues ISO 27001 certified?

No. We do not claim certification. We discuss the controls and evidence required for the engagement with your team.

Where does our data live?

This is established for the selected architecture and services. We distinguish your application environment from external model processing, connected services, logging and backups.

How do you control what an AI agent can do?

The scope defines permissions, allowed tools, approval requirements and failure handling. The implementation and evaluation need to check those boundaries; a written instruction alone is not an access control.

Will our data be used for model training?

Model-training use must be checked against the specific provider, product, account settings and agreed data use. Training, service processing and retention are different questions. Any project-specific fine-tuning would need to be explicitly scoped and agreed.

Can you meet our compliance requirements?

We assess your requirements against the proposed implementation and identify what can be supported and what needs further work. The project scope cannot replace your organisation’s legal, compliance or security approval.

Who can see the data and the audit trail?

Access is defined for the relevant systems and roles. During scoping, we establish the required permissions and review how the chosen platform handles administrative access, records and retention.

Have a requirement we should review?

Tell us the platform, type of workflow and requirement you need to address. We will discuss the right people and information to involve before access or implementation begins.

This page helps you prepare a security review. It does not establish that a particular deployment is compliant.