Governed private AI with reviewable evidence at every layer.

Iftah is built for enterprise review: encryption, RBAC, SSO, audit logging, network isolation, and AI-specific controls are ready today. Formal certifications are on the roadmap; customer-led security review is actively welcomed during procurement.

Read moreاقرأ المزيد

Iftah is built for enterprise review: encryption, RBAC, SSO, audit logging, network isolation, and AI-specific controls are ready today. Formal certifications are on the roadmap; customer-led security review is actively welcomed during procurement.

Where we stand today

  • Architecture-level security in place — encryption, RBAC, SSO, audit
  • ISO 27001 + SOC 2 Type II on active roadmap
View 2 more proof points
  • ISO 42001 (AI lifecycle and governance) planned after ISO 27001
  • Customer-led penetration tests welcomed during procurement

Certifications roadmap

Clear about certification status and review evidence.

We will not list certifications we do not hold. The platform is built with enterprise controls now; formal audits follow the company roadmap and customer procurement requirements.

In progress

ISO 27001

In progress — gap assessment complete. Architecture controls in place. Target certification: [Q4 2026].

View 3 more details

In progress

SOC 2 Type II

Type I audit scheduled. Observation window in progress. Target Type II: [H1 2027].

Planned

ISO 42001

Planned after ISO 27001 completion. Maps to AI lifecycle, model governance, and accountability. Becoming a de facto procurement requirement for AI vendors to government entities.

Available today

Customer-led review

Available at procurement — before contract signature. Security architecture, network diagram, threat model, and deployment documentation provided for your team to review and test.

Available now

How our security review works in procurement.

We invite your security team to review before you sign — not after.

Read moreاقرأ المزيد

We invite your security team to review before you sign — not after.

01
Week 1–2

Architecture review

We provide a network diagram, data-flow document, threat model, and deployment architecture for your security team to review before any procurement decision.

02
Week 2–4

Penetration testing

You can conduct your own penetration test against a staging deployment in a dedicated environment. No NDA clause preventing you from using findings in your procurement process.

03
Week 4–6

Control validation

Your security reviewers validate our control claims against spec — encryption standards, access logs, audit trail, network isolation. We provide the evidence; you verify it.

Architecture-level security

What's in place today, not on a roadmap.

These are the controls customers can review and validate during procurement — independent of certification status.

AES-256 / TLS 1.3

Encryption

AES-256 at rest. TLS 1.3 in transit. Standard cryptographic patterns inside the customer's environment.

View 4 more details

RBAC + SSO

Access control

Role-based access with fine-grained permissions. SSO via SAML 2.0 and OIDC. Customer-owned identity provider.

Every action

Audit logging

Every request, policy decision, model action, and admin event audit-logged. Prompt and response content follows the trace mode your team approves.

Standard K8s

Network isolation

Namespace isolation, secrets management, network policies (ingress/egress), and air-gapped cluster support via standard Kubernetes.

Per-agent identity binding, WORM audit

Identity & agent governance

Every AI agent call carries a signed identity. No agent acts without an explicit, logged policy allow. Closes the shadow AI governance gap.

AI-specific protections

Controls designed for AI threat models, not just web app risk.

Generic enterprise security is necessary but not sufficient for AI workloads. These controls are designed specifically for the AI attack surface.

Prompt injection defenses

Multi-layered detection at gateway and model layer — configurable filtering and policy enforcement before model invocation. Addresses OWASP LLM Top 10 #1 risk for enterprise deployments.

View 3 more details

Output filtering

Customer-defined content policy enforcement, topic restrictions, and output guardrails — applied before every response. Your security team sets the rules; Iftah enforces them.

Configurable model output logging

Full trace, redacted trace, sampled trace, or metadata-only mode — you choose what is logged and where it lives. Essential for NIST CSF Domain 2 and NIST 800-53 access-trail requirements.

Data poisoning detection

Validation pipelines for fine-tuning datasets, anomaly detection, and provenance tracking — keeps your model integrity inside your perimeter.

What your CISO will want to know about AI-specific risk.

Output filtering and content policy enforcement are applied before every response. Customer-defined rules. Logs of filtered content retained in your environment, not ours.
Multi-layer detection at both the gateway and model layer. Sanitisation and policy enforcement run before model invocation — not as a post-hoc filter that can be bypassed.
Full trace mode: every prompt, response, token count, latency, model version, identity, and policy outcome logged in your environment. You choose the logging mode and retention policy — we have no access to the logs.
Iftah Gatekeeper is default-deny on every agent call. No agent acts without an explicit, logged policy allow. Unauthorised attempts are logged with full context — identity, requested action, denial reason, and timestamp.

US regulatory alignment

Architecture designed to support the regulations you're accountable to.

We do not claim certified compliance with regional regimes — compliance is the data controller's obligation. The deployment model gives customers controls and evidence for reviews against the US HIPAA, HIPAA, DIFC, ADGM, Qatar data protection expectations, and financial-sector security expectations.

Data residency controls

Customer-selected region and provider. You control what data exits the perimeter — all exports require explicit customer approval.

View 2 more details

Audit-ready logging

Requests, policy decisions, model actions, and admin events are logged with timestamp, identity, and policy outcome.

Access governance

Identity-bound permissions, service account isolation, and reviewable access patterns mapped to regulator expectations.

Next step

Review Iftah AI against your environment before choosing the first workload.

Book an architecture review