QX Labs Is Now ISO 27001 Certified
QX Labs has achieved ISO 27001:2022 certification. Here's what the audit covers, and how we think about securing AI agents that do real work.
QX Labs is now ISO 27001:2022 certified. An independent auditor has examined our information security management system and confirmed it meets the leading international standard for information security.
A lot of work sits behind this. Here's what the certification actually covers, why it matters if you're putting AI agents to work on your company's data, and a look at how we approach security on a platform where AI can take action on our behalf.
Key takeaways
- QX Labs holds ISO 27001:2022 certification, verified by an independent audit.
- The certification covers our information security management system: the policies, controls, and day-to-day processes that govern how we protect customer data.
- More information on our security posture, including SOC 2, CASA Tier 2 and GDPR is available via our Trust Center.
- Securing AI agents takes more than encrypting data. Permissions, credential isolation, sandboxing, and traceable runs all matter, and we cover how we think about each below.
What does ISO 27001 actually certify?
ISO 27001 is a standard for how an organisation manages information security, and certification applies to the whole company rather than a single product feature. The thing being audited is the information security management system (ISMS): a running system of risk assessments, security policies, access reviews, vendor checks, incident response procedures, and staff training, with evidence that all of it happens in practice.
The 2022 revision of the standard is the current one, and it updated the control set for how companies operate today, including cloud services and threat intelligence.
Certification is also not a one-off. Auditors return for surveillance audits, so the system has to keep working long after the certificate is issued. That ongoing pressure is honestly the most valuable part. A policy document proves little; a control that survives repeat inspection proves a habit.
For customers, the practical effect is simpler: when your security team reviews QX, a large part of their questionnaire is already answered by an accredited third party rather than by us marking our own homework.
Why this matters more for AI agents
Most software security conversations are about data: who can see it, where it's stored, how it's encrypted. Those questions still apply to QX, and our security page covers our answers, from TLS 1.2+ and AES-256 encryption through role-based access and SSO.
But agents raise a second set of questions that classic SaaS reviews don't ask. An agent doesn't only read your data; it sends the email, updates the CRM record, runs the code. So the honest question for any agent platform is: what is this software allowed to do on my behalf, and how would I know if it did the wrong thing?
We think about that in four layers.
Agents only get the access you grant
Every integration an agent uses is one your team explicitly connected, and you control which actions are available to it. Access within your workspace follows the same logic: owner, admin, and member roles decide who can build, run, and configure. If something changes, revoking an integration cuts the agent off immediately.
Credentials get special treatment. Connection secrets are encrypted at rest and resolved only at execution time, which means the model itself never sees them. This is a deliberate design choice, because language models process untrusted input all day. A model that never holds a secret can't be tricked into revealing one.
Untrusted code runs in a sandbox
When agents execute code, it runs in isolated, per-organisation sandboxes with no shared file system. The assumption baked into that design is pessimistic on purpose: treat generated code as potentially misbehaving and limit the blast radius accordingly. We've written before about what agent sandbox escapes look like and why isolation boundaries deserve scrutiny.
Your data stays inside boundaries you set
You choose exactly which files and folders get indexed into Knowledge, rather than granting blanket access and hoping for the best. We don't train models on your content, and our AI providers operate under no-training terms for QX traffic. Enterprise plans can go further with an isolated tenant.
Every run leaves a trail
Agent runs on QX are logged and inspectable: inputs, outputs, and the steps in between. You shouldn't have to take an agent's word for what it did, and on QX you don't. For a broader discussion of agent risk, see Are AI agents safe?
What's next
ISO 27001 is a milestone, not the finish line. We also hold CASA Tier 2 certification for application and API security, our GDPR data processing agreement is available on request, and more is in the works.
Everything is documented in one place: our Trust Center has our controls, policies, subprocessor list, and a security FAQ, with fuller documentation available under NDA. If your security team has questions we haven't answered there, email security@qxlabs.com and we'll get back to you.
And if you're evaluating QX and want to see the controls in context, the security page is the short version, or you can book a demo and put your hardest questions to us directly.
See what AI agents can do for your team
Deploy agents that can act across your data and 1,000+ apps.