Trust Center ·
Blankstate is the independent measurement layer for interactions. The same standard we ask of the systems we observe — deterministic, honest, accountable — applies to the way we run the company. This is the single place to read what we publish, see our certification status, and request the confidential corpus under NDA.
Posture
The Blankstate ecosystem is operated to a control baseline aligned with ISO/IEC 27001, SOC 2 Trust Services Criteria, and NIST CSF. Controls are continuously enforced in the platform itself and continuously evidenced through audit logs, telemetry, and periodic internal review. The platform persists no personal data beyond what is structurally necessary to operate it — sign-in identifiers and user-profile records for authenticated platform users. Interaction content is processed into deterministic, projected measurements ("energy"); the original content is not persisted, and the measurements themselves carry no PII. Cloud and on-premise deployments are both available under the same architectural commitments.
Self-hosted authentication, AES-256-GCM encryption of sensitive fields, instant cross-store token revocation, and a glass-box deterministic measurement model are operative today. Continuous internal vulnerability scanning runs against every build; a formal CREST-accredited external penetration test is scheduled for 2026. Blankstate's compliance portfolio is progressively expanded in line with the company roadmap.
Certifications & standards
Cyber Essentials
CertifiedUK NCSC scheme — Cyber Essentials certification held; cyber insurance in force. Cyber Essentials Plus pathway scoped for the following cycle.
ISO/IEC 27001
In processInformation Security Management System. Scope, Statement of Applicability, Risk Management Framework, Gap Analysis, and Internal Audit Plan already maintained internally.
ISO/IEC 42001
In processAI Management System. AIMS scope, AI System Inventory, AI Impact Assessment template, and Model Cards already maintained internally.
SOC 2 (Type II)
In processTrust Services Criteria mapped against the current control set; engagement to follow ISO 27001 certification.
ISO/IEC 27701
DeferredPrivacy Information Management. Re-evaluated after ISO 27001 certification; the underlying privacy controls are operative today (see BKS-DPP-001).
NIST AI RMF
AlignedOperating practice aligned to the NIST AI Risk Management Framework; see BKS-AI-001.
Public corpus
Six policies are public by design. Each is named by its BKS-XXX-0XX reference so it can be cited directly in due-diligence questionnaires, contracts, and audit findings.
BKS-DPP-001
Data Protection & Privacy Policy
Controller and processor obligations under UK GDPR. Zero personal-data retention by design. Designated DPO.
Read
BKS-SUB-001
Sub-Processor List
The third parties that may process customer personal data on our behalf, where they sit, and how changes are notified.
Read
BKS-AI-001
Responsible AI & AI Governance
We measure AI; we do not generate it. Deterministic, self-hosted, no third-party LLM in the data path. Anchored to ISO 42001 / NIST AI RMF / EU AI Act.
Read
BKS-ESG-001
ESG & Sustainability
Low-compute, low-water architecture as a structural advantage. Diversity, supply chain, tax, and governance commitments.
Read
BKS-COC-001
Code of Conduct & Ethics
Integrity, respectful workplace, conflicts of interest, social media, AI tool use, and Speak-Up.
Read
BKS-MSS-001
Modern Slavery Statement
Voluntary statement, below the £36m statutory threshold. Zero-tolerance position; supply-chain due diligence.
Read
Confidential corpus
The following policies are released under NDA on request. They make up the remainder of the Blankstate InfoSec corpus and are the documents customers usually ask for in technical due diligence.
Request · security@blankstate.ai
Contact
We respond to security and due-diligence requests directly. For incident reports, vulnerability disclosure, and DPA negotiation, use the address below.
Data-subject requests, processor / controller questions — the DPO.
security@blankstate.aiDue-diligence questionnaires, vulnerability disclosure, incident reports.
fair@blankstate.aiResponsible-AI and AI-governance questions — see BKS-AI-001.
speakup@blankstate.aiConfidential, accepts anonymous reports — see BKS-WHB-001.