• Docs
  • Login
Talk to an expertTry for free
Blog
Blog
BlogProductCase studiesNewsInsights
Blog

Trust you can verify: security assurance for the AI era

securityAIUpsun DispatchAgentic SDLCAI Agents
19 August 2026
Tayo Adeniyi
Tayo Adeniyi
Director of Risk and Audit
Share
This post is also available in German and in French.

When you choose a cloud platform, you're entrusting a provider with sensitive business information, customer data, critical applications, and a growing share of your operational resilience. Increasingly, you are also entrusting it with AI. And that changes the questions you should be asking.

Marketing claims cannot answer these questions. Independent evidence can. Here is what that evidence looks like at Upsun and why it matters to your next supplier review.

Assurance you can put in front of your auditors

Upsun holds accredited ISO/IEC 27001:2022 certification and maintains a SOC 2 Type 2 examination report covering security, availability, and privacy. Our compliance program also includes PCI DSS Level 1.

These forms of assurance answer complementary questions:

ISO 27001 confirms that information security is managed through a structured, risk-based management system with defined responsibilities, continuous monitoring, and improvement over time. Not a collection of disconnected technical controls.

SOC 2 Type 2 goes further than a point-in-time badge. It provides independently examined evidence that the controls in scope operated effectively over a sustained reporting period.

For your security and procurement teams, the practical value is direct: recognized, independently-assessed documentation that accelerates vendor due diligence and lets you focus your assessment on the risks and configurations specific to your own use of the platform rather than chasing unsupported vendor statements.

Behind the reports sit the operational controls themselves: hardened runtime environments, read-only file systems, encrypted data paths, network isolation, role-based access control, multi-factor authentication, automated TLS, managed platform updates and audit logging.

One point of honesty that any credible provider owes you: cloud security is a shared responsibility. Upsun manages controls within the platform; you remain responsible for your applications, data, code, integrations and access decisions. A certified provider does not make your application compliant; it gives you a stronger, evidenced foundation on which to demonstrate your own controls.

AI raises the bar. Most providers are not ready.

Traditional assurance covers access control, encryption, monitoring, incident response, and change management. Those controls remain essential. But AI introduces governance questions they were never designed to answer: what context an AI system receives, what permissions it holds, when human approval is required, how outputs are validated, and how decisions can be reconstructed after the event.

ISO/IEC 42001, published in 2023, is the management-system standard built for exactly this. It requires organizations to govern AI through defined accountability, transparency, traceability, and continual improvement. It is not a guarantee that an AI system will never produce a wrong answer as no compliance standard can promise that. Its value is proving that AI operates under governance.

Upsun is on the journey towards pursuing ISO 42001 certification. More importantly, the principles behind it such as risk assessment, accountability, human oversight, traceability, and monitoring, are already embedded in how we build.

Governance by design: Upsun Dispatch™

This is not theoretical for us. Upsun recently introduced Upsun Dispatch™, a platform for the agentic software development lifecycle, where AI agents and humans ship software together through defined workflows, rather than agents operating as unsupervised tools on individual laptops.

Dispatch was designed around the governance questions your risk team will ask:

  • Agents run in isolated cloud environments, not on personal machines where production secrets and tool access spread with no record of what each agent touched.
  • Work moves through your defined workflow, one step at a time, integrating with the tools your teams already use, such as GitHub, GitLab, Linear and Jira.
  • Workflows stop where a human needs to decide. Speed doesn’t override control.
  • Every run keeps a logged record, including cost, so that activity can be reviewed, not reconstructed from memory.

The principle is simple: you should not have to choose between AI-enabled development speed and appropriate human control. 

As part of our continuing assurance roadmap, Upsun Dispatch is scheduled to be brought into the scope of our ISO 27001 and SOC 2 assurance program. This reflects our commitment to extending the same disciplined approach to governance, risk management, security, and auditability across new products and emerging technology use cases.

For customers, this means Dispatch is being developed not only as an AI-enabled productivity platform, but as a governed operating model for agentic software delivery; one designed with security teams, compliance teams, developers, and business leaders in mind.

Six questions to ask any AI-enabled provider

As AI enters your software supply chain, hold every provider, including us, to the same standard:

  1. Who is accountable for AI systems and the decisions made about their use?
  2. What data and context do AI systems access, and how is it protected?
  3. Where is human oversight applied -  review, approval, escalation?
  4. Can activity be traced sufficiently to support investigation and assurance?
  5. How is performance monitored as models, use cases, and risks evolve?
  6. How are third-party models and suppliers governed?

Providers who can answer these with evidence deserve your trust. 

See the evidence

Certification is a milestone. The real discipline is what happens after it: risks evolve, products change, and controls must be continuously tested and improved. That discipline is the real product of an assurance program.

Our current SOC 2 Type 2 report is available on request through your Upsun account representative and our ISO 27001 certification and wider compliance program are documented in our Upsun Trust Center.

But trust is not earned through a certificate alone, at Upsun we believe that it is earned by consistently turning commitments into controls, controls into evidence, and evidence into confidence.

Stay updated

Subscribe to our monthly newsletter for the latest updates and news.

Your greatest work
is just on the horizon

Free trial