Aikido

Aikido Security achieves ISO 42001:2023 certification for AI governance

Written by

Aikido Security has achieved ISO 42001:2023 certification, the international standard for AI management systems, a step few security vendors have taken so far. The certification confirms that Aikido runs a structured, continuously improving governance system for managing the risks introduced by its AI-enabled features, across our entire platform.

What is ISO 42001?

ISO 42001:2023 is the first AI governance framework built specifically for independent, third-party certification. Where ISO 27001 covers information security broadly, ISO 42001 sets requirements for how an organization builds, deploys, and monitors AI systems responsibly, and for keeping that governance current as the AI itself changes.

These requirements include defining system boundaries, establishing an AI policy with clear governance roles, conducting formal risk and impact assessments, tracking AI behavior metrics, and remediating nonconformities and driving continuous updates as models and environments evolve. 

ISO 42001 certifies that Aikido has a functioning, audited management system for governing the risks that any AI features introduce, covering how those risks are documented and monitored day to day. It is designed to be applicable across all AI systems and contexts. 

Why we pursued ISO 42001 certification

As agentic products increase in usage, accountability shifts left to the developers of the systems, rather than the users of the tools. So it’s important to demonstrate trustworthiness of a non-deterministic system by independently assuring the SDLC behind it. By achieving ISO 42001, Aikido is proving that we are building reliable, trustworthy AI systems. 

For example, Aikido’s AI pentesting reasons through applications the way an attacker would, while Code Security Audit reasons over source code to catch what pattern-based tools. We have various other AI tools outlined below. 

Aikido asks customers to trust it with autonomous AI testing of their applications, and AI used to support identifying, triaging and fixing vulnerabilities. Getting our own AI governance independently certified shows that our customers can trust us to govern AI robustly.  We take our customers’ security very seriously, and we want to ensure ethical and responsible use of AI. 

Security and compliance teams evaluating any AI-enabled vendor now ask about governance and data handling as a matter of course. Regulation is following suit, with frameworks like the EU AI Act prompting procurement teams to require proof of AI governance before bringing a new AI tool in-house, even from vendors the framework doesn't directly regulate. For European enterprise buyers specifically, EU AI Act compliance has become a standing item in vendor risk reviews.

What's in scope

ISO 42001 at Aikido covers the complete suite of AI-enabled features across the platform, spanning both software and hardware: AI pentesting (Aikido Attack, Aikido Infinite), on-prem AI pentesting (Aikido Machine), Code Security Audit, Deep PR Review, API scanning, Aikido Libraries, Aikido Images, AutoFix, AutoTriage, Aikido Intel, AI Cloud Search and Code Quality. Any new AI feature introduced in the future at Aikido will follow the same audited processes and governance. 

How we got there

The certification followed the same general path as any ISO management-system audit: an internal readiness review, a documentation-focused stage 1 audit checking that policies and procedures actually meet the standard, and a stage 2 audit that tests whether the governance system holds up under real control testing. Any non-conformities found along the way have to be remediated, or have a documented remediation plan, before certification is granted.

Having already built out SOC 2 and ISO 27001, Aikido had a lot of the underlying process and documentation in place. What was new for ISO 42001 was mapping the AI layer specifically, tracing how each AI feature reaches a decision and what data feeds it, then putting monitoring in place to keep watching that over time. 

Getting here took real collaboration across compliance, development, and GTM, and has strengthened our work with our cloud and AI partners. 

What this means if you're evaluating an AI security vendor

If you're bringing an AI-enabled security tool into a regulated environment, ISO 42001 gives you an independently audited answer to whether its AI risks are actually governed, instead of a vendor's own assurance.

Independently assessed AI governance is still uncommon across the security tooling market. Most vendors selling AI-enabled products still point to company-wide SOC 2 as their only compliance signal, but SOC 2 covers general security controls. A dedicated AI governance certification, one that speaks to how a vendor's AI specifically is governed, is far less common. 

This is usually as a result of bureaucracy and slower speeds indicative of a company’s culture. It’s in Aikido’s DNA to ship quickly and provide customers with a high-level of assurance. This is why we’ve achieved certification here.  

FAQ

Does ISO 42001 certification mean Aikido's AI is safe? ISO 42001 certifies that Aikido has a functioning, audited management system for governing the risks its AI features introduce. That's a certification of the governance system. It doesn't certify that any individual AI model or output is safe.

How is ISO 42001 different from SOC 2? SOC 2 assesses general security controls across a company. ISO 42001 is specific to AI: how an organization documents and monitors the risks its AI systems introduce, and how that governance keeps up as the AI changes.

Is ISO 42001 the same as AI governance software? AI governance software is a category of tools companies use to track and manage AI risk internally. ISO 42001 is an independent, third-party certification that audits whether that governance actually works, regardless of which tools a company uses to run it.

Request our certificate

Aikido is ISO 27001:2022, ISO 42001 & AICPA's SOC 2 Type II compliant, and is actively implementing FedRAMP. We are in full compliance of GDPR. 

If you're evaluating Aikido as part of a compliance review, you can request our ISO 42001 certification through our trust center

Share:

https://www.aikido.dev/blog/aikido-iso-42001-certification

Subscribe for news

4.7/5
Tired of false positives?

Try Aikido like 100k others.
Start Now
Get a personalized walkthrough

Trusted by 100k+ teams

Book Now
Scan your app for IDORs and real attack paths

Trusted by 100k+ teams

Start Scanning
See how AI pentests your app

Trusted by 100k+ teams

Start Testing

Get secure now

Secure your code, cloud, and runtime in one central system.
Find and fix vulnerabilities fast automatically.

No credit card required | Scan results in 32secs.