17.09.2026

Calvin Risk Achieves ISO 27001 Certification

Calvin Risk has acquired ISO 27001 certification, the internationally recognized standard ascertaining soundness in operating an information security management system (ISMS).

Shelby Carter
Associate Project Manager

Zurich, 17 September 2026 - Calvin Risk is pleased to announce that it has acquired ISO/IEC 27001:2022 certification, the internationally recognized standard ascertaining our soundness in operating an information security management system (ISMS). The certification covers the ‘Development secure operations and technical support of the Calvin platform for AI governance, risk management, and model testing’ and was awarded by LL-C Certification Group following an independent assessment.

‍

Information security has been a core consideration in how we've built and operated Calvin from the beginning. Our software supports customers in assessing AI systems, managing governance information and working with model- and use-case-specific data. Due to the nature of our work, achieving ISO/IEC 27001 certification not only formally recognizes the information security practices and controls already embedded across our operations, but provides an additional layer of assurance for customers and their legal, procurement, and information-security teams.

‍

ISO 27001 is a risk based, structured approach to information security. It includes implementation of the following:

  • Information-security risk assessment
  • Access and identity management
  • Incident response
  • Business continuity/disaster recovery
  • Supplier/third-party risk
  • Employee security awareness
  • Vulnerability management
  • Secure development
  • Logging and monitoring

‍

As AI itself introduces new security and data risks, our strategy has always centered around an airtight baseline. With AI systems becoming increasingly embedded in enterprise operations and business-critical processes, securing the infrastructure surrounding such systems becomes just as important as assessing the systems themselves.

‍

This formal certification allows us to communicate the work we have consistently invested in over the years, instantly.

‍

In all, we are pleased to now host ISO’s international standard, allowing us to provide an additional layer of assurance for customers and their legal, procurement and information-security teams during vendor assessments, standardizing the security and compliance review process as we onboard new customers.

‍

Security was never a checkbox for us, it's the reason customers can trust us with their model and governance data in the first place. ISO 27001 just puts a formal stamp on practices we've had in place since day one.

- Syang Zhou, CTO & Founder @ Calvin Risk

‍

Customers use Calvin to assess and track some of their most critical AI systems and governance evidences. Having ISO 27001 adds an independent layer of tangibility to our security commitment; effectively, it is a concrete way confirming to customers how security is built into what we do, from our systems to their data.

- Shelby Carter, DPO & Associate Project Manager @ Calvin Risk

Ready to assure your AI systems? Learn how your systems behave and make them trustworthy by design.

Risk & compliance

Establish continuous, defensible oversight

Business leaders

Scale AI without hidden risk