Compliance & assurance

Achieved vs aligned.
We say it honestly.

What we hold, what we're actively pursuing, and where the architecture is aligned. Each one dated and sourced. Nothing else.

Held credentials

What we currently hold.

Achieved

Talastron is a signatory of the Armed Forces Covenant.

Talastron has signed the Armed Forces Covenant, a pledge to support the armed forces community and treat those who serve, or have served, with fairness and respect.

Last reviewed
Owner
Marketing Lead, Talastron
Achieved

Talastron holds Cyber Essentials certification.

Talastron is certified under the UK government-backed Cyber Essentials scheme, demonstrating baseline controls against common cyber threats. The certificate is held under the company’s prior registered name, Orion Data Analytics Ltd, now Talastron Ltd.

Last reviewed
Owner
Marketing Lead, Talastron
Achieved

Talastron is registered with the Information Commissioner's Office as a data controller (registration ZB804967).

Talastron is registered with the UK Information Commissioner’s Office under the Data Protection Act, as required of organisations that process personal data.

Last reviewed
Owner
Marketing Lead, Talastron
Achieved

Talastron participates in the Microsoft ISV Success Program.

Participation in the Microsoft ISV Success Program supports Talastron Kinetic AI’s engineering and publication path towards the Azure Marketplace.

Source
Microsoft ISV Success Program — enrolment record
Last reviewed
Owner
Marketing Lead, Talastron
Achieved

Talastron is a Microsoft Partner (Partner ID 7100919).

Talastron holds active Microsoft Partner status (Partner ID 7100919), in the Microsoft AI Cloud Partner Program and the ISV Success Program. This underpins Talastron Kinetic AI’s delivery model: manufactured software running inside the customer’s own Microsoft Azure tenant.

Source
Microsoft AI Cloud Partner Program, Partner ID 7100919
Last reviewed
Owner
Marketing Lead, Talastron
In progress

What we're actively pursuing.

In progress

Talastron is actively pursuing ISO/IEC 27001 certification for Talastron Kinetic AI's delivery pipeline.

Talastron Kinetic AI’s gated, governed pipeline maps its controls to ISO/IEC 27001, and certification work is under way against that mapping. This is a pursuit-in-progress statement — it will move to “Achieved” once the certificate is issued, not before.

Source
Talastron Kinetic AI architecture and ISMS control mapping
Last reviewed
Owner
Marketing Lead, Talastron
How we talk about credentials

We never inflate aligned into achieved.

Every regulatory, partnership and certification claim on the site is factually current and reviewed before publication. 'Achieved' is reserved for credentials we hold; 'In progress' means we're actively pursuing it, with work under way; 'Aligned to' describes how the architecture is built, with no certification claim attached. We won't call anything ISO 27001 certified until it is.

AI Trust, Risk & Security Management · AI TRiSM

The Five-Gate Model is Talastron's implementation of AI TRiSM.

AI TRiSM is Gartner's framework for ensuring that agentic AI systems operate reliably, securely, fairly, and in compliance with data-privacy regulations. The Five-Gate Manufacturing Model implements all four pillars at defined, human-approved gates — not as an afterthought, but as the production process itself.

01

Explainability & Model Monitoring

Trust

Every AI output is adversarially reviewed by Themis before it reaches a human gate. The Dual-Judge pattern — Primary Judge then Formatting Judge — ensures outputs are accurate, complete, and interpretable before any human is asked to approve them. The WAF scorecard at Gate 5 is a live readiness assessment of the deployed system, not the design.

Gates 1c · 2c · 4c · 5
02

ModelOps & Governance

Operations

The Five-Gate pipeline enforces end-to-end lifecycle governance on every agent output. Gate 3 applies ISO 42001 AI governance controls — explainability, bias assessment, model risk — before any infrastructure is built. Azure ML model lineage is captured and transferred to the client at Gate 5 as part of the IP handover.

Gates 3 · 5 · ISO 42001
03

AI Application Security

Security

Vulcan generates AVM-first Bicep with zero hardcoded secrets, no public endpoints on data or AI services, and tagging lock on every resource. Cassandra cross-checks every predicted deployment change against Nemesis's live Azure Policy constraints before Gate 4 opens. No resource reaches the client's tenant without policy verification.

Gates 3 · 4 · NCSC CAF · ISO 27001
04

Data Privacy & Ethics

Risk

All data remains inside the client's Azure tenant — zero egress, UK South sovereign. Gate 1 classifies PII, IP, and regulated data before architecture is designed. UK GDPR data minimisation and purpose limitation are applied at Gates 1 and 3. Consumer Duty explainability is verified at Gate 5 for regulated financial deployments.

Gates 1 · 3 · 5 · UK GDPR · FCA Consumer Duty

How Talastron references AI TRiSM in analyst briefings: The Five-Gate pipeline wraps probabilistic LLM reasoning in deterministic validation contracts, context-isolated agent boundaries, and automated DevSecOps policy checks before any code or action reaches enterprise production systems. This is Talastron's implementation of the AI TRiSM framework.

Procurement-friendly. Audit-ready. Dated.

Book the 1-hour Executive
live demonstration.

Bring a real requirement. We build a working architecture together and you walk out with a spec and a fixed-price commitment.

Or email us directly at hello@talastron.ai