Trust & Compliance
Certifications, regulatory alignment, and where to find every trust document
1. Certifications and Standards Alignment
| Standard | Status | Covers |
|---|---|---|
| ISO/IEC 27001:2022 | Certified, maintained through annual surveillance audits | Information security management across our people, processes, and technology |
| ISO/IEC 42001 | Certified, maintained through annual surveillance audits | Responsible AI management — model risk assessment, human oversight, and governance |
2. Regulatory Alignment, by Region
NSOffice.AI currently operates in India and the United Kingdom. We do not operate in, or transfer data to, any other jurisdiction.
- India — aligned with the Digital Personal Data Protection Act, 2023, including a designated Grievance Officer.
- United Kingdom — aligned with the UK GDPR and Data Protection Act 2018. See our UK Privacy Addendum.
For the full picture of how we approach regulation across both regions, see Our Approach to AI Regulation.
3. Data Residency Commitments
- Data belonging to Indian organizations is stored and processed exclusively on servers in India; data belonging to UK organizations is stored and processed exclusively on servers in the United Kingdom. We do not move stored data between regions.
- When a request draws on your organization's connected business systems, the platform retrieves that information in real time rather than keeping a separate, long-term copy outside your region.
4. How We Handle AI Processing
- Every AI request is screened by our guardrails layer — which detects and redacts personal data and checks for unsafe content — before it reaches an AI model.
- We do not use your organization's content to train our own or any third-party provider's general-purpose AI models. See Your Data & Model Performance for detail.
- Every AI model used on the platform goes through a risk assessment and approval process before it's used in production, with defined human oversight.
5. Data Protection and Platform Security
Your organization's data is held in a logically isolated environment, separate from every other customer's, protected by encryption at rest and in transit, role-based access control, and enterprise authentication (passwordless, MFA, SSO). See our Security Overview for the full detail.
6. Vendor Transparency
We publish the sub-processors we rely on to deliver the platform, including which of them are AI model providers that only ever receive guardrail-screened content. See our Sub-processor List, which we update as our vendor relationships change.
7. Ongoing Oversight
Our security program is subject to regular internal review and independent audit as part of our ISMS, with defined processes for incident response, business continuity, and continuous improvement — not a one-time setup.
8. Legal and Trust Documents
- Privacy Policy
- Terms of Service
- Usage Policy
- Cookie Policy
- Data Processing Agreement
- Sub-processor List
- Our Approach to AI Regulation
- Security Overview
Have a specific compliance question, or need documentation for a vendor security review? Contact customersupport@nsoffice.ai — our team supports customer due diligence directly.