The standards we work to
An authority or enterprise buying an AI agent needs to know which rules the system was built against - and, just as much, what has not been tested yet. This page carries both: the Israeli and international standards we work to, and the honest status of each one.
We hold no certification for any standard on this page, and we say so before you ask. "We work to it" means the system and the procedures were built against its requirements and that we can hand you the material for review - not that an external body has certified us. A standard marked as a target is exactly that: a declared target, not yet tested.
How to read these tables
- Working to it
- The system and procedures are built to the standard, and there is material we can hand over for review. Not a certification.
- Declared target
- We are building toward it. Not yet tested, and not backed by external evidence.
- Tracking
- Relevant, or becoming relevant. Not implemented today, and we will not imply otherwise.
Information security and risk management
The base every other standard rests on: how data is stored, who reaches it, and what happens when something goes wrong.
-
ISO/IEC 27001:2022
Working to itAn information security management system (ISMS) - policy, procedure, risk management and controls
What you can receive: An ISMS pack of 57 written policies and procedures, under version control. No certificate.
-
ISO/IEC 27002:2022
Working to itThe control set itself - 93 security controls
What you can receive: The control mapping inside that same ISMS pack
-
OWASP Top 10 / ASVS
Working to itThe application security verification standard for web systems
What you can receive: Automated security scanning on every code change, and A+ in two external tests you can re-run
-
OWASP Top 10 for LLM Applications
Declared targetRisks specific to language-model systems - prompt injection, data leakage and misuse
-
NIST Cybersecurity Framework 2.0
Declared targetA cyber risk framework - Govern, Identify, Protect, Detect, Respond, Recover
-
ISO/IEC 27017 and 27018
Declared targetSecurity and privacy controls specific to cloud services
-
Israeli National Cyber Directorate defence doctrine
Declared targetThe Israeli defence framework for engagements with public bodies
-
SOC 2 Type II
TrackingAn external audit of security, availability and confidentiality controls
Privacy and personal data
Resident and employee data. Israeli regulation here tightened substantially in August 2025.
-
Israel's Privacy Protection Law, 5741-1981, including Amendment 13
Working to itThe binding Israeli law. Amendment 13 took effect on 14.08.2025 and widened appointment, documentation and enforcement duties
What you can receive: A privacy policy, a data-processing policy and a controlled retention and deletion policy
-
Privacy Protection (Data Security) Regulations, 5777-2017
Working to itConcrete security duties for databases - separation, permissions, access logging and incident reporting
What you can receive: Separation between customers at the system level - every query is filtered by customer - role-based permissions and a full audit log
-
GDPR (EU) 2016/679
Working to itThe European privacy regulation - lawful basis, data-subject rights and a processing agreement
What you can receive: A data-processing agreement (DPA) you can sign, and the option of storage inside the EU
-
ISO/IEC 27701
Declared targetA privacy information management system (PIMS), extending 27001
Digital accessibility
An inaccessible widget is a legal exposure for the authority, not only for us. So the status here is stated precisely: we build to WCAG, but we have not yet passed an external accessibility audit against Israeli standard 5568.
-
Equal Rights for Persons with Disabilities (Service Accessibility) Regulations, 5773-2013
Working to itMandatory digital-service accessibility in Israel, including handling accessibility reports
What you can receive: A published accessibility statement and a commitment to fix a reported issue within 60 days
-
WCAG 2.1 Level AA
Declared targetThe international web accessibility standard - contrast, keyboard navigation, alternative text and screen readers
-
Israeli standard 5568
Declared targetThe Israeli web content accessibility standard, based on WCAG
What you can receive: No external accessibility audit has been carried out. We claim nothing further.
-
EN 301 549
TrackingThe European accessibility standard for public ICT procurement
-
WCAG 2.2
TrackingThe newer revision - additional focus, target size and input assistance requirements
Responsible AI and transparency
The youngest area, and the one where the bar is rising fastest. Israel is not in the EU, but European requirements already appear in Israeli tenders.
-
EU AI Act, Article 50
Working to itFrom 02.08.2026: a person must be told they are talking to an AI system
What you can receive: The agent identifies itself as an AI system, and every answer shows the source it came from
-
ISO/IEC 42001:2023
Declared targetAn AI management system (AIMS) - the first certifiable standard in the field. It plugs straight into the 27001 pack
-
NIST AI RMF 1.0
Declared targetA voluntary AI risk management framework. The language AI control documents are written in today
-
ISO/IEC 23894
TrackingGuidance on risk management for AI systems
-
UK ATRS
TrackingAn algorithmic transparency record - mandatory in UK government departments from 2025
Quality, continuity and operations
What happens when a server falls over, and how you prove the service was run properly over time.
-
ISO 22301 (business continuity)
Declared targetA disaster recovery plan, RTO/RPO targets and proven backups
What you can receive: Full off-server backups every 6 hours, and a documented full restore drill that runs automatically every week - restore, build, boot and actually serve; the last drill passed on 2026-08-23. Cutting production over to the standby site is still a manual step and has not yet been exercised end to end.
-
ISO/IEC 20000-1
TrackingIT service management - incidents, changes and service levels
-
ISO 9001
TrackingA quality management system
What we are not claiming
- We hold no certification for any standard on this page. Not ISO 27001, not ISO 42001, not SOC 2.
- No external accessibility audit against Israeli standard 5568 has been carried out. Until one is, it is a target and not compliance.
- We do not publish uptime percentages or quality metrics that were not measured by a source we can point you at.
- A standard marked "tracking" is not implemented today, and we will not word it as if it were.
What you can receive for review
- The full ISMS pack - 57 policies and procedures
- A data-processing agreement (DPA) ready to sign
- The accessibility statement and the route to our accessibility coordinator
- The results of both external security tests, which you can re-run at any time
- The full capability catalogue, itemised and pinned to a version
Need the material for a tender or a vendor review?
We will hand over the whole document pack, including the parts that are not finished yet.
Talk to usLast updated: 2026-08-20
Talk to Us
Schedule a live product demo, ask a general question, or set up a business consultation. Pick what fits and we'll come back to you shortly.