Skip to main content

Trust Center

One place for our certifications, security controls, and compliance documentation. Independently verified where possible, transparent everywhere else.

Active frameworks
3
ISO 27001:2022, GDPR and ISO 42001
Active controls
94
Managed in our ISMS
Automated checks
84
Continuously monitored across our infrastructure
Policy completion
100%
Approved ISMS policies

Figures from our compliance platform (Tidal Control), as of 2026-07-02.

Verify our ISO 27001 certificate yourself, no NDA required

Our certificate is listed in the public register of Kiwa, an RvA-accredited certification body. Certificate number K-0229199/1, valid from 13 May 2026 until 12 May 2029. Scope: development, management and support of the AI platform for law firms in Europe.

View the certificate at Kiwa

Frameworks & independent assurance

  • ISO 27001:2022

    Certified by Kiwa. Annual surveillance audits.

    Certified
  • GDPR

    Managed as an active framework in our ISMS, with a data processing agreement for every customer.

    Active framework
  • Penetration testing & responsible disclosure

    Annual independent pentests by NCC Group (Fox-IT), summary under NDA. Plus an ongoing responsible disclosure programme via security@andri.ai.

    Annual + ongoing
  • ISO 42001

    AI Management System: certification track in progress.

    In certification

Documentation

Publicly available

Available under NDA

  • NCC Group (Fox-IT) penetration test management summary
  • Data processing agreement template and sub-processor register
  • Tenant isolation architecture document
  • Internal EU AI Act classification memo (limited risk)

Request via info@andri.ai. We respond to security questionnaires at no additional cost.

Security questions?

Report a security incident or vulnerability, or ask a due diligence question:

security@andri.aiinfo@andri.ai