TRUST CENTRE
Block8.ai delivers AI-powered, human-validated penetration testing to organisations that need to prove their security posture. This page sets out how Block8.ai protects its own — the certifications held, how client data is handled, who processes it, and how to obtain the documentation your review requires.
___
-
Block8.ai’s certifications are held with independent bodies and can be verified directly with them.
ISO/IEC 27001:2022 — Certified
Block8.ai operates an Information Security Management System certified to ISO/IEC 27001:2022, the international standard for information security management. The certification is independently audited and subject to ongoing surveillance.
Certification body: Southpac Certifications
Certification date: May 2026
Certificate number: 1586 ISMS
Scope: AI-driven penetration testing and security reporting services
Issued: 20 May 2026
Download ISO 27001 Certificate (PDF) HERE.
Verify on the JAS-ANZ Register HERE.
A CREST ANZ Approved Member Company
Block8.ai is A CREST ANZ Approved Member Company. CREST is the international not-for-profit accreditation body for the technical information security industry; approval requires independent assessment of testing methodology, data handling and personnel vetting. Membership can be verified on the CREST register.
Verify our CREST membership HERE.
Certification Status
ISO/IEC 27001:2022 — Certified
CREST — A CREST ANZ Approved Member Company
SOC 2 Type II — In progress. Audit expected Q1 2027
-
Our Security Commitment
Block8.ai maintains an ISO 27001:2022 certified Information Security Management System covering all aspects of our penetration testing and reporting services. Our ISMS is independently audited and subject to ongoing surveillance by Southpac Certifications.
We enforce multi-factor authentication for all personnel, encrypt all data in transit and at rest using industry-standard cryptography, and operate exclusively from Australian datacentres to maintain data sovereignty. Client environment data encountered during testing is processed in-memory and is not persisted beyond the active engagement. Block8 retains engagement findings data including proof of concept, observations, and remediation tracking which are needed for report generation and retesting, subject to the same encryption and access controls as all other confidential data.
Our security program includes regular penetration testing of our own infrastructure, CREST-certified testing personnel, mandatory background checks, quarterly access reviews, documented incident response procedures, and comprehensive cyber insurance coverage.
-
All client and operational data is hosted in Australian datacentres. AI processing is performed within the AWS ap-southeast-2 region over private network connectivity — engagement data is not transmitted across the public internet for AI processing.
-
Two distinct categories of client data are handled differently.
Client environment data encountered during testing — system responses, captured traffic, and credentials and configuration observed in the target environment — is processed in memory for the duration of the active engagement and is not retained afterwards.
Engagement findings data — vulnerability records, proof of concept evidence, observations and remediation status — is retained for 12 months following delivery of the final report, to support the client’s remediation and retest cycle. Findings data is encrypted in transit and at rest and is subject to the same access controls as all other confidential information. Clients may request earlier deletion in writing at any time.
Full detail of our data classification, retention schedule and deletion procedures is available in our security documentation package on request: security@block8.ai
-
Privacy Policy
Block8.ai’s privacy policy sets out what personal information is collected, how it is used and how to make a privacy enquiry. It is published at block8.ai/privacy-policy.
Data Processing Agreement (DPA)Block8.ai’s Data Processing Agreement is available to clients and prospective clients on request.
Request our DPA: security@block8.ai -
For detailed security information — including comprehensive cyber insurance coverage, encryption standards, recovery objectives, architecture details, and compliance questionnaire responses — request access to our security documentation package:
-
Block8.ai engages the third parties below to deliver its services. Each is assessed before engagement and is bound by contractual obligations covering data protection, breach notification and data deletion.
Amazon Web Services (AWS)
Service provided: Cloud infrastructure, compute and AI processing
Data processed: Platform infrastructure data; engagement data during active processing
Hosting region: ap-southeast-2 (Sydney, Australia)
Certifications: SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, FedRAMP, PCI DSS
Anthropic (accessed via AWS Bedrock)
Service provided: AI model services for analysis and report generation
Data processed: Engagement data in transit for processing — zero retention by Anthropic, no model training on customer inputs
Hosting region: ap-southeast-2 (Sydney, Australia), private network connectivity
Certifications: SOC 2 Type II
Supabase
Service provided: Managed database and application services
Data processed: Application data, authentication data, session data
Hosting region: AWS ap-southeast-2 (Sydney, Australia)
Certifications: SOC 2 Type II, ISO 27001
Microsoft 365
Service provided: Email, collaboration and identity services
Data processed: Client contact information, business communications, identity data
Hosting region: Australia
Certifications: SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, FedRAMP
Key Controls
All subprocessors hold current SOC 2 Type II or ISO 27001 certification, or both
Data is processed in Australian regions where available
Contractual obligations for data protection, breach notification and data deletion
Anthropic: zero data retention, no model training on customer inputs
Change Notification
Block8.ai will notify clients of any material change to this subprocessor list with a minimum of 30 days’ advance notice, by email or client portal notification.
Architecture Detail
Detailed system architecture, network topology, encryption standards and recovery objectives are provided under NDA as part of our security documentation package: security@block8.ai
Page Metadata
Subprocessor list last updated: August 2026
Page owner: security@block8.ai
Last reviewed: August 2026 — Next scheduled review: February 2027
-
Security, privacy and documentation enquiries are handled by monitored mailboxes rather than individuals, so requests are not delayed by leave or handover.
Security enquiries & documentation requests:
security@block8.aiPrivacy enquiries:
privacy@block8.ai