Trust & Verification

AICS Trust Center

This page explains how the AI Control Standard works, how assessment determinations are made, how organizations maintain status, and how third parties verify credentials.

What this page provides

A structured explanation of the assessment and registration workflow, public status verification, lifecycle monitoring, standards alignment, and the request path for new assessments.

For buyers
Understand what AICS evaluates and how status is verified.
For procurement
Review lifecycle, governance domains, and public verification model.
For registered organizations
Use the public status record and verification page to share current governance status.
Enterprise Trust Layer

Security, evidence protection, and governance transparency at a glance

AICS presents trust information in layers: a concise overview for business stakeholders, expandable technical details for IT/security reviewers, and curated assistant responses for common procurement questions.

Evidence Protection

Private evidence workflows

Uploaded governance artifacts are handled through authenticated client portal workflows and are separated from public registry verification.

Access Control

Authenticated access paths

Client portal access, administrative operations, and public verification are intentionally separated by workflow and system purpose.

Backend Protection

Server-side sensitive operations

Privileged workflows are intended to execute through protected backend functions rather than browser-exposed logic.

Public Verification

Public verification metadata only

The public registry validates recognition status without exposing uploaded evidence, policies, procedures, or internal governance files.

Governance Workflow

From client onboarding to public verification

The AICS workflow is designed to keep client evidence private while supporting controlled review, recognition publication, and public status verification.

01

Client Onboarding

Client access is provisioned so evidence can be submitted through a controlled portal workflow.

02

Secure Evidence Upload

Governance artifacts are uploaded into the client workspace for assessment support.

03

Governance Review

AICS reviews evidence against governance domains and operational readiness expectations.

04

Administrative Approval

Approval and issuance workflows are handled through administrative pathways, separated from public pages.

05

Public Verification

Public verification metadata is made available for registry lookup and third-party verification.

Technical & Governance Details

Expandable details for IT, security, and procurement reviewers

These sections provide depth without overwhelming the page. Reviewers can expand the topics most relevant to their security or governance questions.

Shared Responsibility Model
AICS secures
  • Application platform and trust workflow
  • Protected storage architecture and database access paths
  • Authentication workflows and client portal access patterns
  • Governance workflows for assessment, approval, issuance, and verification
  • Public registry boundaries and public verification metadata exposure
Client secures
  • Endpoint devices used to access the client portal
  • User credential hygiene and password protection
  • Internal governance policies and evidence ownership
  • Internal approval decisions before uploading sensitive artifacts
  • Personnel access decisions within the client organization
Security Design Principles

Least Privilege

Access is limited to the minimum level required for the relevant client or administrative workflow.

Defense in Depth

Controls are layered across frontend delivery, backend execution, database policies, storage access, and workflow separation.

Segregation of Duties

Administrative workflows are separated from client-facing evidence submission and public verification experiences.

Operational Isolation

Public registry and verification pages are isolated from private client evidence and internal governance artifacts.

Auditability

Governance workflows are designed to support traceability across request, review, approval, and issuance stages.

Controlled Access Paths

Sensitive operations use protected backend pathways instead of exposing privileged actions directly in browser code.

Why Client Evidence Is Not Publicly Accessible
Public verification exposes

Public verification metadata

  • Recognition status
  • Recognition or request identifier
  • Recognition date and validity metadata
  • Registry verification details
  • Organization-level recognition display information
Private workspace protects

Client governance evidence

  • Uploaded governance documents
  • Policies, procedures, meeting minutes, and artifacts
  • Internal assessment support materials
  • Client-specific evidence workflow records
  • Protected review and recognition document workflows
Credential & Key Protection

Frontend Uses Public-Safe Access

Browser-facing code may use public Supabase access configuration combined with Row-Level Security policies. This is different from exposing privileged service-role credentials.

Service-Role Credentials Stay Server-Side

Privileged service-role keys are intended only for protected server-side functions and should not appear in HTML, client JavaScript, screenshots, or public repositories.

Backend Functions Handle Sensitive Workflows

Operations such as assessment request creation, portal access delivery, and recognition publication can run through protected Netlify Functions.

No Overclaiming

AICS does not claim to eliminate all cybersecurity risk. The platform uses layered controls, controlled workflows, and shared responsibility practices to reduce risk.

Authentication, Database Security & RLS

Authenticated Sessions

Client workspaces require authenticated portal access for evidence upload, assessment status visibility, and recognition document access.

Row-Level Security

Supabase Row-Level Security supports database-level restrictions so records can be segmented by client identity, workflow role, and authorized access path.

Storage Boundaries

Evidence storage and registry verification are separated so public pages do not function as evidence repositories.

Administrative Isolation

Administrative workflows are separated from public verification pages and client-facing evidence submission experiences.

Interactive Trust Guidance

AICS Governance & Security Assistant

Select a common IT/security question below. Responses are curated to keep trust, security, and governance statements consistent.

Ask about security, evidence protection, and recognition workflows

This assistant provides controlled, pre-approved explanations for common IT, procurement, and governance review questions.

Curated Responses

Is client evidence publicly accessible?

No. AICS public verification systems are designed to expose public verification metadata only. Uploaded evidence and internal governance documents remain within authenticated client evidence workflows.

  • Public registry pages are for recognition validation, not evidence disclosure.
  • Client evidence is handled through protected portal workflows.
  • Database access controls and storage boundaries support evidence separation.
Security note: AICS avoids claims such as “zero risk” or “unhackable.” The platform communicates layered controls, controlled access paths, and shared responsibility.

Assessment and Recognition Process

The AICS Governance Assessment follows a structured, evidence-based process designed for executive visibility, control maturity assessment, and public trust.

01
Preliminary Scoping
Define organizational scope, AI usage boundary, and assessment objective.
02
Evidence Submission
Organizations submit governance documents, policies, and supporting artifacts.
03
Control Domain Evaluation
Assessment scoring is performed across the five AICS governance domains.
04
Executive Reporting
Delivery of a structured governance score, operational observations, remediation roadmap, and executive impact summary.
05
Assessment Determination
Eligible organizations receive a registered governance status and public status record.

Registration & Public Verification

Organizations with an AICS registration receive a public status record that third parties can independently verify.

AICS Public Status Record

The public status service presents the organization’s registration identifier, current governance status, scope, and applicable dates without issuing a customer display mark.

Verification path
Public status lookup → Registration record → Current governance status
Visible signals
Registration ID, current status, scope, and validity period
Primary use
Independent verification, procurement review, and governance transparency

Public Registry & Verification Model

The AICS public registry allows third parties to confirm whether an organization’s registration status is active, expired, or otherwise not currently valid.

Live
Public Registry
Verified
Status Records
Direct
Direct Status Lookup

Registration Status Definitions

Organizations listed in the AICS Public Registry are assigned a registration status reflecting the current standing of their governance assessment.

Active Registration Status

The organization has completed an AICS Governance Assessment and currently maintains an active registration status. Registration status remains subject to continued alignment and periodic review.

Expired Registration Status

Registration status has lapsed due to the end of the assessment cycle without follow-up review. The organization may pursue re-assessment to restore status.

Withdrawn Registration Status

Registration status has been withdrawn due to material governance deficiencies, misrepresentation, or failure to maintain required controls.

Assessment and Registration Lifecycle

AICS registration status reflects a lifecycle designed to support ongoing governance maturity.

Initial Assessment

Assessment of governance controls, structured scoring, and governance status determination.

Annual Recognition Review

Light-touch annual review to confirm controls remain active and governance expectations continue to be met.

Follow-Up Assessment

Periodic reassessment with updated evidence and a renewed recognition cycle.

Standards Alignment

AICS governance is informed by recognized governance, risk, and control frameworks relevant to responsible AI adoption.

NIST AI RMF
ISO Governance Principles
Responsible AI Best Practices

NIST and ISO are referenced for informational alignment only. AICS is an independent assessment and readiness framework and is not affiliated with or endorsed by these organizations.

AICS Control Domains

Control Categories

Governance & Accountability • Data Governance & Input Controls • Output Validation & Decision Controls • Vendor & Model Risk Oversight • Monitoring & Executive Attestation

Enterprise FAQ

Common security, evidence, and recognition questions

These answers are designed for buyers, IT reviewers, procurement teams, and organizations evaluating whether AICS is appropriate for their governance needs.

Are client documents or uploaded evidence publicly accessible?

No. Public registry and verification pages expose only public verification metadata such as recognition status, recognition date, validity information, and verification details. Uploaded evidence, internal policies, procedures, and governance artifacts remain part of the protected client evidence workflow.

What does the public registry show?

The public registry is designed to verify recognition status. It may display organization name, recognition identifier, status, validity period, and related verification information. It is not designed to publish private evidence files or internal governance documents.

How is evidence protected during the assessment process?

Evidence is handled through authenticated client portal workflows and separated from public-facing verification pages. Access controls, protected storage patterns, and Row-Level Security concepts support separation between client evidence, administrative workflows, and public registry records.

Is uploaded evidence shared with AI models?

AICS is designed to support controlled governance review workflows. The client-facing evidence workflow should not be positioned as a public AI training pipeline. If automated analysis capabilities are used in the future, AICS should clearly define the review process, data handling boundaries, and client-facing disclosures.

What is Row-Level Security?

Row-Level Security, often called RLS, is a database access control approach that restricts which records a user can read or modify. In an AICS context, this supports the principle that clients should only access records tied to their authorized account and workflow.

How does AICS use the Statement of Applicability concept?

A Statement of Applicability-style view helps clarify which governance controls are applicable, not applicable, implemented, partially implemented, or pending evidence. This gives leadership, IT, and compliance reviewers a clearer view of scope, rationale, and evidence linkage.

Is AICS the same as ISO/IEC 42001 certification?

No. AICS is an independent AI governance assessment and readiness framework. AICS may be informed by recognized governance concepts and AI management system principles, but it should not be represented as ISO/IEC 42001 certification or official ISO accreditation unless a separate formal accreditation path is completed.

What do clients receive from an AICS assessment?

Clients receive governance readiness observations, evidence review results, maturity scoring, executive impact analysis, remediation priorities, an assessment determination, and public verification assets when recognition is published.

Request an AICS Governance Assessment

Organizations interested in recognized AICS status may request an AICS Governance Assessment.

Back to Top
After submission, you will receive an AICS Request ID for public status lookup.