CivAI well on its way to ISO 27001 and ISO 42001 certification
Good news about our certification processes. CivAI is working towards certification for ISO 27001 and ISO 42001, and both processes are on track. The stage 1 audit has been scheduled. Our ambition is clear. In the third quarter, or at the latest the fourth quarter of 2026, we aim to be fully certified.
Two standards, one goal
ISO 27001 is the international standard for information security. The certificate demonstrates that data security is systematically safeguarded—in technology, processes, and the organisation.
ISO 42001 is the standard for responsible AI management. This standard sets requirements for how an organisation develops, manages, and continually improves AI systems, with attention to transparency, risk management, and human oversight.
Together, they form exactly the combination that fits what we build: secure and sovereign AI environments for education, government, and healthcare.
Why this matters
Schools, governments, and healthcare institutions want to be able to trust the AI solutions they use. Rightly so. With these certifications, that trust will soon be independently verifiable.
Our solutions, such as EduGPT, GovGPT, OrgGPT, and CareGPT, run entirely on European infrastructure, without reliance on major foreign platforms. The certification also makes verifiable on paper what we already practise in reality.
Additionally, the Edu-V process is underway for EduGPT, also expected to be completed in the third quarter of 2026.
Next steps
Once completed, we will publish the certificates and the corresponding scope on our website, so everyone can view them.
If you would like to know more about our approach to information security and responsible AI right now, please feel free to contact us. We are happy to tell you more about it.
Photo BalticServers.com via Wikimedia Commons, CC BY-SA 3.0