Trust Centre
We practise what we preach
As a world leader in AI security, our own security posture is non-negotiable. Here’s how we protect your data, our platform, and your trust.
Trusted by security teams at
Accreditations
Independently certified
Audited and certified against recognised international standards.

Cyber essentials
UK government-backed cyber security certification.
- Certification body
- Iasme
- Audited by
- DigitalXRaid
- Certificate
- 2f7b427d-b1c5-4dd3-9a98-4fa16e74cbc9

Cyber Essentials Plus
UK government-backed cyber security certification.
- Certification body
- Iasme
- Audited by
- DigitalXRaid
- Certificate
- 95ffaa0a-5516-4ee5-b85e-6457310b4910

ISO 27001:2022
Accredited Information security management system.
- Certification body
- NQA
- Audited by
- NQA
- Certificate
- 218933
Documents
The evidence behind every claim on this page
Audit reports, certificates and policies — the primary sources your security review will ask for. Public documents download straight away; the rest take a single approval that covers all of them.
Compliance
- Cyber Essentials Certificate
- Cyber Essentials Plus Certificate
- ISO 27001:2022 Certificate
- AI Platform Pentest Report 2026Request access to download this document
Legal
- Employers Liability Insurance CertificateRequest access to download this document
Infrastructure documentation
- Architecture DiagramRequest access to download this document
- Data Flow DiagramRequest access to download this document
Security controls
How we protect your data
18 controls across 6 domains. Search, or select a domain to read the detail.
Availability
What we commit to, and what we deliver
We back availability with a 99.9% SLA, and publish the measured record against it — 90 days of component-level history from our own monitoring, not a summary of it.
Sub-processors
Disclosed in full
Every vendor that processes customer data on our behalf, what each one handles, and where it sits.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Platform hosting | UK / EU |
| Anthropic | Processes very limited client data for analytics, platform maintenance, development support and issue diagnosis. | US |
| Hotjar | Session recording to understand user interactions and diagnose issues | EU |
| SendGrid | Sending transactional emails to permitted users | EU / US |
| Sentry | Crash and error logs to facilitate diagnosis | US |
FAQ
Common questions
The questions we're asked most often, answered plainly.
Data handling
Legal
AI transparency
How we use AI
Which models we use, what customer data reaches them, and what never does.
MODELS
AI Model Use
CultureAI uses a small number of third-party large language models run on AWS Bedrock to power specific analysis features within the product. We currently use OpenAI's GPT-5.2 and GPT-4o mini, Amazon's Nova and Anthropic's Claude Sonnet 4.5 and Claude Haiku 4.5.
TRAINING
We do not train on your data
Client data is never used for training models.
Want to learn more about what we do?
This page covers how we secure our own platform. To see what that platform actually does, start on the main site.