Gabaltech is not currently certified against the frameworks below. We reference them because they shape how we design AI governance today, and because we expect some of them to become procurement requirements for our customers. This page will be updated as our certification posture changes โ we won't claim a certification we don't hold.
| Framework | Our current posture |
|---|---|
| EU AI Act | Design principles (risk-based approach, human oversight, transparency) inform our practices. Not a certification. |
| ISO/IEC 42001 (AI management systems) | Reviewed as a reference model for AI governance structure. Not certified. |
| ISO 27001 | Reviewed as a reference model for our information security practices. Not certified. |
| SOC 2 | SOC 2 principles (security, availability, confidentiality) inform our controls. No SOC 2 report issued. |
| NIST AI Risk Management Framework | Used as a reference for our risk assessment and mitigation approach โ see AI Risk Management. |
| OWASP Top 10 for LLM Applications | Used to inform our AI security practices โ see AI Security. |
| OWASP ASVS | Referenced where relevant to application security controls surrounding AI features. |
Why this matters
Enterprise procurement and security review teams increasingly ask about AI governance specifically, separate from general information security. We'd rather be precise about where we are โ genuinely aligned in practice, not yet formally certified โ than overstate our position and have that surface in a security questionnaire later.
What's next
As Gabaltech grows and as these standards mature, we expect to pursue formal certification where it's the right fit for our customers. We'll update this page when that changes.