
Security & trust
How does Softblues approach AI security and data protection?
Security starts with the task, the information involved and the systems it touches. We work with your team to define access, data flows, permitted actions and operational responsibilities for the engagement. Controls depend on the chosen platform and implementation, and are agreed as part of the scope.
- OpenAI Select Partner
- Google Cloud Services Partner
- Claude Partner Network Certified
- Member of the Microsoft AI Cloud Partner Program
What controls do we scope with you?
Six areas, agreed with your team rather than assumed. What is available in each depends on the chosen platform and implementation.
Where will data be stored and processed?
The answer depends on the deployment, platform, model endpoint and connected services. An application hosted in your cloud account can still send information to a model provider or another service. Storage location, processing location and retention need to be examined separately.
During scoping, we identify the relevant data flows and requirements with your IT or security team. Provider documentation and the terms for the selected service determine which controls are available.
A provider’s certification does not certify Softblues or your complete solution.
What should a security review cover?
Six areas to establish before access or implementation begins. Use it to prepare your own review rather than as evidence that one has been passed.

| Area | What to establish |
|---|---|
| Information | Data categories, approved sources and sensitive fields |
| Access | Authorised people, service identities and permissions |
| Providers | Selected services, processing locations and applicable terms |
| Actions | Allowed operations, approval points and exception handling |
| Evidence | Test scope, logging coverage and access to records |
| Operation | Retention, change control, support and incident responsibilities |
Send the requirements or questionnaire you need us to address. We will identify the relevant scope, available documentation and any gaps to resolve.
Do not include credentials or sensitive records in the initial contact form.
What is Softblues' certification status?
Softblues is not ISO 27001 certified. Our security approach is informed by ISO 27001 principles, with the controls and responsibilities for an engagement defined during scoping.
Certification claims for any hosting or model provider should be checked separately against the actual service being used.
What has this looked like in an audit?
An anonymised AI-built application audit identified a storage-access exposure before go-live. The urgent exposure was closed and the wider rebuild was proposed separately. It illustrates why access must be checked at the service and data layers, as well as in the interface.
Stage: audit delivered; rebuild proposed. It is one engagement, not evidence about every build.
Security and trust: at a glance
- Certification
- Softblues is not ISO 27001 certified. The approach is informed by ISO 27001 principles, with controls and responsibilities defined during scoping.
- What we scope
- Access and permissions, data handling, action boundaries, testing and evaluation, logging and monitoring, and handover and operation.
- Storage and processing
- Depends on the deployment, platform, model endpoint and connected services. Storage location, processing location and retention are examined separately.
- Logging
- Which events are recorded, who may inspect them, how long they are retained and who responds to an alert are agreed. Coverage varies by platform and implementation.
- Model training
- Checked against the specific provider, product, account settings and agreed data use. Any project-specific fine-tuning would be explicitly scoped and agreed.
- Provider certifications
- A provider's certification does not certify Softblues or your complete solution. Check it against the actual service being used.
- Compliance
- We assess your requirements against the proposed implementation. The project scope cannot replace your organisation’s legal, compliance or security approval.
Common questions about security
Is Softblues ISO 27001 certified?
No. We do not claim certification. We discuss the controls and evidence required for the engagement with your team.
Where does our data live?
This is established for the selected architecture and services. We distinguish your application environment from external model processing, connected services, logging and backups.
How do you control what an AI agent can do?
The scope defines permissions, allowed tools, approval requirements and failure handling. The implementation and evaluation need to check those boundaries; a written instruction alone is not an access control.
Will our data be used for model training?
Model-training use must be checked against the specific provider, product, account settings and agreed data use. Training, service processing and retention are different questions. Any project-specific fine-tuning would need to be explicitly scoped and agreed.
Can you meet our compliance requirements?
We assess your requirements against the proposed implementation and identify what can be supported and what needs further work. The project scope cannot replace your organisation’s legal, compliance or security approval.
Who can see the data and the audit trail?
Access is defined for the relevant systems and roles. During scoping, we establish the required permissions and review how the chosen platform handles administrative access, records and retention.
Have a requirement we should review?
Tell us the platform, type of workflow and requirement you need to address. We will discuss the right people and information to involve before access or implementation begins.
This page helps you prepare a security review. It does not establish that a particular deployment is compliant.