Ctrl AI
Technology shaped
by operational experts
Information security

Built to be trusted

Enterprise-grade security and data governance, independently certified and assured for handling sensitive legal evidence.

Cyber Essentials PlusISO/IEC 27001Certified · 2022Crown Commercial Service Supplier

Our security principles

Certification

ISO 27001 certified

Our information security management system is independently certified to the ISO 27001 standard.

Data residency

UK storage, EU processing

Client data is stored in the UK and processed within the EU. Nothing leaves the region.

AI governance

No model training

Your data is never used to train AI models, yours or anyone else’s. It stays your data.

Encryption

Encrypted at rest and in transit

All data is encrypted both at rest and in transit using industry-standard protocols.

Isolation

Client data segregation

Each client’s data is logically segregated, isolating matters and preventing cross-client access.

Access

SSO or MFA authenticated

Access is secured through single sign-on or multi-factor authentication for every user.

Assurance

CREST-accredited penetration testing

The platform is regularly tested by CREST-accredited penetration testers.

Security by design

Sensitive evidence handled to the standards the legal sector demands.

AI governance

AI that stays under your control

Ctrl AI prepares the work and your people make the decisions. Governance is built into how the platform works, from the way assessments are set up to the record of every review.

No prompt box

Users do not type free-form prompts into the platform. Open prompting means every person asks a different question in a different way and gets a different answer, which is an operational risk. Each assessment is a defined task, configured to your rules or playbook, so every case is assessed against the same questions.

Tested in evaluations

Every assessment and output is subject to rigorous testing in our evaluation platform, against closed cases with known outcomes. Tests run before release and again whenever a model, instruction or configuration changes.

Risk flags in the evidence

Page-level detection flags illegible text, signs of deception, inconsistencies between documents and attempted prompt injection, so a person sees the risk before anyone relies on that evidence.

Human verification

A named person verifies every assessment before it is used. Each finding shows its reasoning and cites the page it relies on, and the reviewer can amend or override it.

Monitoring and audit

Every action on a case is logged. Your organisation can see how people use AI, what they verified, edited and overrode, and monitor AI performance over time.

Request our infosec pack

Our security pack covers ISO 27001, Cyber Essentials Plus, our data processing agreement and our information security controls, for your security, information governance and procurement teams.

Request our infosec pack