In progress
ISO 27001
In progress — gap assessment complete. Architecture controls in place. Target certification: [Q4 2026].
Iftah is built for enterprise review: encryption, RBAC, SSO, audit logging, network isolation, and AI-specific controls are ready today. Formal certifications are on the roadmap; customer-led security review is actively welcomed during procurement.
Read moreاقرأ المزيدShow lessعرض أقلIftah is built for enterprise review: encryption, RBAC, SSO, audit logging, network isolation, and AI-specific controls are ready today. Formal certifications are on the roadmap; customer-led security review is actively welcomed during procurement.
Where we stand today
Certifications roadmap
We will not list certifications we do not hold. The platform is built with enterprise controls now; formal audits follow the company roadmap and customer procurement requirements.
In progress
In progress — gap assessment complete. Architecture controls in place. Target certification: [Q4 2026].
In progress
Type I audit scheduled. Observation window in progress. Target Type II: [H1 2027].
Planned
Planned after ISO 27001 completion. Maps to AI lifecycle, model governance, and accountability. Becoming a de facto procurement requirement for AI vendors to government entities.
Available today
Available at procurement — before contract signature. Security architecture, network diagram, threat model, and deployment documentation provided for your team to review and test.
Available now
We invite your security team to review before you sign — not after.
Read moreاقرأ المزيدShow lessعرض أقلWe invite your security team to review before you sign — not after.
We invite your security team to review before you sign — not after.
We provide a network diagram, data-flow document, threat model, and deployment architecture for your security team to review before any procurement decision.
You can conduct your own penetration test against a staging deployment in a dedicated environment. No NDA clause preventing you from using findings in your procurement process.
Your security reviewers validate our control claims against spec — encryption standards, access logs, audit trail, network isolation. We provide the evidence; you verify it.
Architecture-level security
These are the controls customers can review and validate during procurement — independent of certification status.
AES-256 / TLS 1.3
AES-256 at rest. TLS 1.3 in transit. Standard cryptographic patterns inside the customer's environment.
RBAC + SSO
Role-based access with fine-grained permissions. SSO via SAML 2.0 and OIDC. Customer-owned identity provider.
Every action
Every request, policy decision, model action, and admin event audit-logged. Prompt and response content follows the trace mode your team approves.
Standard K8s
Namespace isolation, secrets management, network policies (ingress/egress), and air-gapped cluster support via standard Kubernetes.
Per-agent identity binding, WORM audit
Every AI agent call carries a signed identity. No agent acts without an explicit, logged policy allow. Closes the shadow AI governance gap.
AI-specific protections
Generic enterprise security is necessary but not sufficient for AI workloads. These controls are designed specifically for the AI attack surface.
Multi-layered detection at gateway and model layer — configurable filtering and policy enforcement before model invocation. Addresses OWASP LLM Top 10 #1 risk for enterprise deployments.
Customer-defined content policy enforcement, topic restrictions, and output guardrails — applied before every response. Your security team sets the rules; Iftah enforces them.
Full trace, redacted trace, sampled trace, or metadata-only mode — you choose what is logged and where it lives. Essential for NIST CSF Domain 2 and NIST 800-53 access-trail requirements.
Validation pipelines for fine-tuning datasets, anomaly detection, and provenance tracking — keeps your model integrity inside your perimeter.
US regulatory alignment
We do not claim certified compliance with regional regimes — compliance is the data controller's obligation. The deployment model gives customers controls and evidence for reviews against the US HIPAA, HIPAA, DIFC, ADGM, Qatar data protection expectations, and financial-sector security expectations.
Customer-selected region and provider. You control what data exits the perimeter — all exports require explicit customer approval.
Requests, policy decisions, model actions, and admin events are logged with timestamp, identity, and policy outcome.
Identity-bound permissions, service account isolation, and reviewable access patterns mapped to regulator expectations.
Next step