The standards we operate to
We were asked, in effect, what ProofMemo is built to. Rather than answer with a badge we have not earned, here is the honest version: what we have self-assessed against, where we conform today, and what we are still working toward. The evidence behind each line is real and can be shown to an auditor or a serious broker on request. That it survives being checked is the whole point — it is the same thing the product does for a file.
A first-party declaration under ISO/IEC 17050-1. Self-assessed, not a certification. We hold no third-party certificate today, and we say so. Reviewed 11 September 2026.
ISO/IEC 42001 — AI management
The international standard for managing an AI system responsibly.
Where we conform today. The part of the standard about how the system runs, we meet and we test. The decision path contains no model — the machine records and checks; it never makes the professional call. Documents are classified and the most sensitive fields removed before any model sees them. Every step is labelled by who acts there and whether it touches a person's rights, and the build fails if any step is found deciding on its own. We keep a ranked, working register of the ways our own system could be defeated, and it opens on our worst weakness.
What we are working toward. Certification asks for the management apparatus around those controls — a formal manual, signed roles, a scheduled internal audit, a management review. Those are built and run on a quarterly cadence; independent certification follows once ProofMemo is deployed in the market.
Our AI System Impact Assessment is published in full.
ISO/IEC 27001 — information security
The international standard for information security management.
Where we conform today. The technical controls are strong because the architecture is built for it: the file stays on the broker's own machine while it is read and assessed, so there is no second copy to leak; access to raw identity data is gated; the record is cryptographically signed and can be verified against a key we publish outside the file.
What we are working toward. The organisational half — the full statement of applicability across every control, and the people-security processes — is the work in progress, and independent certification follows it.
SOC 2
SOC 2 is an independent auditor's report produced over a period of observation, not something an organisation declares of itself. We make no SOC 2 claim. We are working toward a SOC 2 Type 2 report over the hosted verification service, and we will name it here when it is issued.
Australia's six practices for AI adoption
We publish a first-party declaration against the National AI Centre's six essential practices, including an honest note of the one we had not yet evidenced. The impact assessment above closes it.