Trust Is Part of the Product: Why ISO 27001 Is on AIamigo's Roadmap
AIamigo has put ISO/IEC 27001 on its roadmap. Learn why documented information security is essential to trust in an AI governance platform.


When an employee uses an AI service, the organisation must be able to trust that sensitive information will not end up in the wrong place.
That is a core part of the problem AIamigo was created to solve. The platform helps organisations control AI use, enforce policies, and protect information before it reaches an external AI service.
But trust has to work both ways.
When we ask customers to trust AIamigo as a security and control layer between their employees and AI services, we must also be able to document how we protect our own systems, access, and supplier relationships.
That is why ISO/IEC 27001 certification is on AIamigo's roadmap.
Our precise status
✓Key takeaways
- Information security is an ongoing management discipline, not a single technical feature.
- AIamigo already has a foundation of risk assessments, access controls, supplier management, and procedures to build on.
- The next phase is about showing that those controls are carried out consistently over time.
- Our goal is certification readiness in 2027 — not making a certification claim ahead of the facts.
Information security is not one feature
Information security is often reduced to technical features such as encryption, strong passwords, and multi-factor authentication.
Those are important measures, but they are not the whole picture.
Security also concerns:
- who can access which systems,
- how access is approved and removed,
- how suppliers are assessed,
- how security incidents are handled,
- how data can be recovered after errors or outages,
- and how the organisation continually checks that its safeguards work.
ISO/IEC 27001 describes the requirements for an information security management system — an ISMS. Its purpose is to make information security a documented, recurring part of operations rather than something that depends on isolated decisions.
We are not starting from zero
AIamigo has already established a substantial part of the foundation.
Among other things, we have:
- mapped the systems and suppliers involved in our operations,
- carried out risk assessments,
- put relevant data-processing agreements in place and recorded them,
- described technical and organisational security measures,
- established individual user access without shared accounts,
- introduced strong passwords and multi-factor authentication,
- centralised the secure handling of access credentials,
- documented procedures for security breaches, deletion, and supplier oversight,
- and located core production data in a European region.
That does not mean the work is complete. It means we have a real foundation to build on.
From described security to documented operation
The next step is not necessarily to introduce a long list of new tools. What matters most is documenting that the controls already in place are applied consistently.
That includes, for example:
- regular user-access reviews,
- documented backup and recovery checks,
- ongoing assessment of critical suppliers,
- follow-up on system changes and security risks,
- recording security incidents — even when there are none,
- training and guidance for people with system access,
- and regular management review of information security.
Time is an important part of this work. A security procedure becomes truly valuable when we can show that it has been used over a sustained period.
But time does not do the work on its own. Evidence must be kept while activities are carried out. Otherwise, decisions and controls that have already taken place may have to be reconstructed later.
Make AI use easier to control
Create a free AIamigo account and start protecting selected sensitive information in supported AI workflows.
What does this mean for our customers?
The goal is not simply to obtain a certificate.
The goal is to make it easier for customers to understand and assess AIamigo's security.
A well-run management system should give customers, among other things:
- clearer evidence of our security work,
- greater transparency around suppliers and data flows,
- more consistent handling of access and changes,
- documented processes for security incidents,
- and confidence that identified risks are followed through.
For larger companies and public-sector organisations, it can also make supplier assessments and security approvals more efficient.
Trust in a security product does not come only from what it can do. It comes from being able to show how the company behind it works securely every day.
— Jan Thomsen, Director and Founder
What does ISO 27001 certification not mean?
Certification does not mean an organisation can never experience a security breach.
It also does not mean that a product or all of its features have been approved by ISO. ISO does not issue certificates itself; certification is carried out by an external certification body.
Instead, certification shows that an organisation has established a system for identifying, treating, and following up on information-security risks within a defined scope.
For AIamigo, the relevant scope would be the development, operation, maintenance, support, and delivery of the AIamigo Platform.
A roadmap is not a certification
Our roadmap
The work towards certification readiness has three broad phases.
1. Consolidation
We bring together and quality-assure our existing documentation, risk assessments, supplier records, policies, and security measures.
2. Documented operation
We carry out and record recurring controls, including access reviews, supplier reviews, recovery tests, and follow-up on security incidents.
3. Audit and certification
Once the management system has been operating and can be evidenced, we will conduct an internal audit, management review, and then an external certification process.
Our goal is to make AIamigo certification-ready in 2027.
Trust needs evidence
A Trust Center, a data-processing agreement, and a security policy are important elements. But trust does not come from documents on a website alone.
It comes from the actions performed every day: how access is managed, how changes are controlled, how suppliers are assessed, and how the company responds when something does not go as expected.
For AIamigo, information security is therefore not only an internal discipline. It is part of the product's value and a prerequisite for the trust our customers place in us.
ISO/IEC 27001 is the natural next step in making that trust more visible and demonstrable.
Build responsible AI use on documented control
Install AIamigo for supported browser workflows and create a free account to make protection of sensitive inputs part of everyday work.
