AI Compliance Vendors
Vendor attestationActiveInternational (ISO)

ISO/IEC 27001 Information Security Management

ISO/IEC 27001 is the international standard for information security management systems (ISMS). It complements ISO/IEC 42001 (AI management systems) and is often held by AI governance vendors as a baseline information-security certification. Required by many enterprise procurement processes globally.

This is an attestation a vendor obtains for its own operations — it is distinct from the AI-specific obligations the vendor’s tooling can help you meet. Vendors hold this certification or they don’t; we don’t use partial-coverage tiers here.

Standard owner

International (ISO)

Typical certification cycle

See overview

Penalty for misrepresentation

Loss of certification; legal exposure

Vendors that hold ISO 27001

Vendors below have a current third-party attestation against this standard. We list the certification, not coverage levels.

5 vendors

VendorHQFoundedSizePricingCoverageLast verified
Scrut AutomationPalo Alto, US202151-200Contact for pricingCertifiedApr 24, 2026
VantaSan Francisco, USA2018500-1000Contact for pricingCertifiedApr 26, 2026
TrustArcWalnut Creek, US1997501-1000Enterprise subscription; contact sales for quote; modular pricing based on scope and modulesCertifiedApr 26, 2026
NaaiaLouveciennes, FR202111-50No public pricing tiers; demo and quote requested via website.AdjacentApr 27, 2026
KnosticHerndon, US202311-50Contact for pricingAdjacentApr 27, 2026

Compare across industries

See which vendors support ISO 27001 in your sector.

Last verified April 24, 2026. Informational summary only — not legal advice. Consult qualified counsel for specific obligations.