Redbo AI

The standards we work to

An authority or enterprise buying an AI agent needs to know which rules the system was built against - and, just as much, what has not been tested yet. This page carries both: the Israeli and international standards we work to, and the honest status of each one.

We hold no certification for any standard on this page, and we say so before you ask. "We work to it" means the system and the procedures were built against its requirements and that we can hand you the material for review - not that an external body has certified us. A standard marked as a target is exactly that: a declared target, not yet tested.

How to read these tables

Working to it
The system and procedures are built to the standard, and there is material we can hand over for review. Not a certification.
Declared target
We are building toward it. Not yet tested, and not backed by external evidence.
Tracking
Relevant, or becoming relevant. Not implemented today, and we will not imply otherwise.

Information security and risk management

The base every other standard rests on: how data is stored, who reaches it, and what happens when something goes wrong.

  • ISO/IEC 27001:2022

    Working to it

    An information security management system (ISMS) - policy, procedure, risk management and controls

    What you can receive: An ISMS pack of 57 written policies and procedures, under version control. No certificate.

  • ISO/IEC 27002:2022

    Working to it

    The control set itself - 93 security controls

    What you can receive: The control mapping inside that same ISMS pack

  • OWASP Top 10 / ASVS

    Working to it

    The application security verification standard for web systems

    What you can receive: Automated security scanning on every code change, and A+ in two external tests you can re-run

  • OWASP Top 10 for LLM Applications

    Declared target

    Risks specific to language-model systems - prompt injection, data leakage and misuse

  • NIST Cybersecurity Framework 2.0

    Declared target

    A cyber risk framework - Govern, Identify, Protect, Detect, Respond, Recover

  • ISO/IEC 27017 and 27018

    Declared target

    Security and privacy controls specific to cloud services

  • Israeli National Cyber Directorate defence doctrine

    Declared target

    The Israeli defence framework for engagements with public bodies

  • SOC 2 Type II

    Tracking

    An external audit of security, availability and confidentiality controls

Privacy and personal data

Resident and employee data. Israeli regulation here tightened substantially in August 2025.

  • Israel's Privacy Protection Law, 5741-1981, including Amendment 13

    Working to it

    The binding Israeli law. Amendment 13 took effect on 14.08.2025 and widened appointment, documentation and enforcement duties

    What you can receive: A privacy policy, a data-processing policy and a controlled retention and deletion policy

  • Privacy Protection (Data Security) Regulations, 5777-2017

    Working to it

    Concrete security duties for databases - separation, permissions, access logging and incident reporting

    What you can receive: Separation between customers at the system level - every query is filtered by customer - role-based permissions and a full audit log

  • GDPR (EU) 2016/679

    Working to it

    The European privacy regulation - lawful basis, data-subject rights and a processing agreement

    What you can receive: A data-processing agreement (DPA) you can sign, and the option of storage inside the EU

  • ISO/IEC 27701

    Declared target

    A privacy information management system (PIMS), extending 27001

Digital accessibility

An inaccessible widget is a legal exposure for the authority, not only for us. So the status here is stated precisely: we build to WCAG, but we have not yet passed an external accessibility audit against Israeli standard 5568.

  • Equal Rights for Persons with Disabilities (Service Accessibility) Regulations, 5773-2013

    Working to it

    Mandatory digital-service accessibility in Israel, including handling accessibility reports

    What you can receive: A published accessibility statement and a commitment to fix a reported issue within 60 days

  • WCAG 2.1 Level AA

    Declared target

    The international web accessibility standard - contrast, keyboard navigation, alternative text and screen readers

  • Israeli standard 5568

    Declared target

    The Israeli web content accessibility standard, based on WCAG

    What you can receive: No external accessibility audit has been carried out. We claim nothing further.

  • EN 301 549

    Tracking

    The European accessibility standard for public ICT procurement

  • WCAG 2.2

    Tracking

    The newer revision - additional focus, target size and input assistance requirements

Responsible AI and transparency

The youngest area, and the one where the bar is rising fastest. Israel is not in the EU, but European requirements already appear in Israeli tenders.

  • EU AI Act, Article 50

    Working to it

    From 02.08.2026: a person must be told they are talking to an AI system

    What you can receive: The agent identifies itself as an AI system, and every answer shows the source it came from

  • ISO/IEC 42001:2023

    Declared target

    An AI management system (AIMS) - the first certifiable standard in the field. It plugs straight into the 27001 pack

  • NIST AI RMF 1.0

    Declared target

    A voluntary AI risk management framework. The language AI control documents are written in today

  • ISO/IEC 23894

    Tracking

    Guidance on risk management for AI systems

  • UK ATRS

    Tracking

    An algorithmic transparency record - mandatory in UK government departments from 2025

Quality, continuity and operations

What happens when a server falls over, and how you prove the service was run properly over time.

  • ISO 22301 (business continuity)

    Declared target

    A disaster recovery plan, RTO/RPO targets and proven backups

    What you can receive: Full off-server backups every 6 hours, and a documented full restore drill that runs automatically every week - restore, build, boot and actually serve; the last drill passed on 2026-08-23. Cutting production over to the standby site is still a manual step and has not yet been exercised end to end.

  • ISO/IEC 20000-1

    Tracking

    IT service management - incidents, changes and service levels

  • ISO 9001

    Tracking

    A quality management system

What we are not claiming

  • We hold no certification for any standard on this page. Not ISO 27001, not ISO 42001, not SOC 2.
  • No external accessibility audit against Israeli standard 5568 has been carried out. Until one is, it is a target and not compliance.
  • We do not publish uptime percentages or quality metrics that were not measured by a source we can point you at.
  • A standard marked "tracking" is not implemented today, and we will not word it as if it were.

What you can receive for review

  • The full ISMS pack - 57 policies and procedures
  • A data-processing agreement (DPA) ready to sign
  • The accessibility statement and the route to our accessibility coordinator
  • The results of both external security tests, which you can re-run at any time
  • The full capability catalogue, itemised and pinned to a version

Need the material for a tender or a vendor review?

We will hand over the whole document pack, including the parts that are not finished yet.

Talk to us

Last updated: 2026-08-20

Talk to Us

Schedule a live product demo, ask a general question, or set up a business consultation. Pick what fits and we'll come back to you shortly.

I'm interested in:
Talk to us on WhatsApp