Skip to content
CultureAI

Trust Centre

We practise what we preach

As a world leader in AI security, our own security posture is non-negotiable. Here’s how we protect your data, our platform, and your trust.

Trusted by security teams at

  • Microsoft
  • Glovo
  • Octopus
  • NVIDIA
  • Annexus Health
  • Smedvig
  • Tatton
  • ITS

Accreditations

Independently certified

Audited and certified against recognised international standards.

Cyber essentials

UK government-backed cyber security certification.

Certification body
Iasme
Audited by
DigitalXRaid
Certificate
2f7b427d-b1c5-4dd3-9a98-4fa16e74cbc9

Cyber Essentials Plus

UK government-backed cyber security certification.

Certification body
Iasme
Audited by
DigitalXRaid
Certificate
95ffaa0a-5516-4ee5-b85e-6457310b4910

ISO 27001:2022

Accredited Information security management system.

Certification body
NQA
Audited by
NQA
Certificate
218933

Documents

The evidence behind every claim on this page

Audit reports, certificates and policies — the primary sources your security review will ask for. Public documents download straight away; the rest take a single approval that covers all of them.

Request access

Compliance

Legal

Infrastructure documentation

Security controls

How we protect your data

18 controls across 6 domains. Search, or select a domain to read the detail.

Availability

What we commit to, and what we deliver

We back availability with a 99.9% SLA, and publish the measured record against it — 90 days of component-level history from our own monitoring, not a summary of it.

Measured over 90 days across 2 components · SLA 99.9%

Component detail and incident history
90 days agoToday

Sub-processors

Disclosed in full

Every vendor that processes customer data on our behalf, what each one handles, and where it sits.

Sub-processorPurposeLocation
Amazon Web Services (AWS)Platform hostingUK / EU
AnthropicProcesses very limited client data for analytics, platform maintenance, development support and issue diagnosis.US
HotjarSession recording to understand user interactions and diagnose issuesEU
SendGridSending transactional emails to permitted usersEU / US
SentryCrash and error logs to facilitate diagnosisUS

FAQ

Common questions

The questions we're asked most often, answered plainly.

Data handling

Legal

AI transparency

How we use AI

Which models we use, what customer data reaches them, and what never does.

MODELS

AI Model Use

CultureAI uses a small number of third-party large language models run on AWS Bedrock to power specific analysis features within the product. We currently use OpenAI's GPT-5.2 and GPT-4o mini, Amazon's Nova and Anthropic's Claude Sonnet 4.5 and Claude Haiku 4.5.

TRAINING

We do not train on your data

Client data is never used for training models.

Want to learn more about what we do?

This page covers how we secure our own platform. To see what that platform actually does, start on the main site.