
When you choose a cloud platform, you're entrusting a provider with sensitive business information, customer data, critical applications, and a growing share of your operational resilience. Increasingly, you are also entrusting it with AI. And that changes the questions you should be asking.
Marketing claims cannot answer these questions. Independent evidence can. Here is what that evidence looks like at Upsun and why it matters to your next supplier review.
Upsun holds accredited ISO/IEC 27001:2022 certification and maintains a SOC 2 Type 2 examination report covering security, availability, and privacy. Our compliance program also includes PCI DSS Level 1.
These forms of assurance answer complementary questions:
ISO 27001 confirms that information security is managed through a structured, risk-based management system with defined responsibilities, continuous monitoring, and improvement over time. Not a collection of disconnected technical controls.
SOC 2 Type 2 goes further than a point-in-time badge. It provides independently examined evidence that the controls in scope operated effectively over a sustained reporting period.
For your security and procurement teams, the practical value is direct: recognized, independently-assessed documentation that accelerates vendor due diligence and lets you focus your assessment on the risks and configurations specific to your own use of the platform rather than chasing unsupported vendor statements.
Behind the reports sit the operational controls themselves: hardened runtime environments, read-only file systems, encrypted data paths, network isolation, role-based access control, multi-factor authentication, automated TLS, managed platform updates and audit logging.
One point of honesty that any credible provider owes you: cloud security is a shared responsibility. Upsun manages controls within the platform; you remain responsible for your applications, data, code, integrations and access decisions. A certified provider does not make your application compliant; it gives you a stronger, evidenced foundation on which to demonstrate your own controls.
Traditional assurance covers access control, encryption, monitoring, incident response, and change management. Those controls remain essential. But AI introduces governance questions they were never designed to answer: what context an AI system receives, what permissions it holds, when human approval is required, how outputs are validated, and how decisions can be reconstructed after the event.
ISO/IEC 42001, published in 2023, is the management-system standard built for exactly this. It requires organizations to govern AI through defined accountability, transparency, traceability, and continual improvement. It is not a guarantee that an AI system will never produce a wrong answer as no compliance standard can promise that. Its value is proving that AI operates under governance.
Upsun is on the journey towards pursuing ISO 42001 certification. More importantly, the principles behind it such as risk assessment, accountability, human oversight, traceability, and monitoring, are already embedded in how we build.
This is not theoretical for us. Upsun recently introduced Upsun Dispatch™, a platform for the agentic software development lifecycle, where AI agents and humans ship software together through defined workflows, rather than agents operating as unsupervised tools on individual laptops.
Dispatch was designed around the governance questions your risk team will ask:
The principle is simple: you should not have to choose between AI-enabled development speed and appropriate human control.
As part of our continuing assurance roadmap, Upsun Dispatch is scheduled to be brought into the scope of our ISO 27001 and SOC 2 assurance program. This reflects our commitment to extending the same disciplined approach to governance, risk management, security, and auditability across new products and emerging technology use cases.
For customers, this means Dispatch is being developed not only as an AI-enabled productivity platform, but as a governed operating model for agentic software delivery; one designed with security teams, compliance teams, developers, and business leaders in mind.
As AI enters your software supply chain, hold every provider, including us, to the same standard:
Providers who can answer these with evidence deserve your trust.
See the evidence
Certification is a milestone. The real discipline is what happens after it: risks evolve, products change, and controls must be continuously tested and improved. That discipline is the real product of an assurance program.
Our current SOC 2 Type 2 report is available on request through your Upsun account representative and our ISO 27001 certification and wider compliance program are documented in our Upsun Trust Center.
But trust is not earned through a certificate alone, at Upsun we believe that it is earned by consistently turning commitments into controls, controls into evidence, and evidence into confidence.