Trust you can verify: security assurance for the AI era
Blog post from Upsun
Upsun argues that independent security assurance is increasingly important for cloud providers handling sensitive data, critical applications, and AI-enabled workflows, citing its ISO/IEC 27001:2022 certification, SOC 2 Type 2 report for security, availability, and privacy, and PCI DSS Level 1 compliance. It distinguishes ISO 27001’s risk-based information security management framework from SOC 2 Type 2’s assessment of control effectiveness over time, while emphasizing that customers retain responsibility for their own applications, data, integrations, and access decisions. The post says AI introduces additional governance needs around data context, permissions, human approvals, traceability, validation, and monitoring, and identifies ISO/IEC 42001 as a relevant emerging AI management standard that Upsun plans to pursue. It presents Upsun Dispatch, an agentic software development lifecycle platform, as incorporating isolated environments, structured integrations, human decision points, and logged activity to support controlled AI-assisted development, with planned inclusion in its ISO 27001 and SOC 2 assurance scope. The post also recommends evaluating AI providers based on accountability, data protection, human oversight, traceability, performance monitoring, and third-party governance, while noting that certifications require ongoing testing and improvement.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.