Trust Center
ISO/IEC 42001
ISO/IEC 42001 certifies a customer's AI management system. It does not certify a product. Corveil is not ISO/IEC 42001 certified, and routing traffic through Corveil does not certify the customer.
This page covers the AI systems you run through Corveil: models, agents, and tools on the gateway. It is a control crosswalk, not a statement of conformity.
The inventory is models, keys, MCP servers, sensors, and workers connected to Corveil. Anything that never hits the gateway is outside that record.
01
Controls a reviewer can ask to see
| Annex A | Corveil control | Artifact |
|---|---|---|
| A.2 Policies related to AI | Guardrails (keyword, regex, PII, custom, and spend limit; block or sanitize), ontology policies, and behavioral guidance. | Guardrail audit event |
| A.3 Internal organization | Organization and team roles, virtual keys, and per-tool allow or deny. | Role or key record, tool grant |
| A.4 Resources for AI systems | The model catalog and per-organization toggles, provider credentials, MCP servers, and worker definitions. | Catalog toggle, credential record (no secret), MCP server record |
| A.6 Operation and monitoring | Request logs, worker-run history, guardrail hits, and usage and cost rollups. This is operation of use, not design or validation of the customer's models. | Log, export, usage rollup |
| A.7 Data | Provenance for organizational knowledge (sensors, source events, and evidence) and PII filtering on the request path. This is not a training-data quality program. | Evidence or source-event record, PII guardrail event |
| A.9 Use of AI systems | Model allow-lists, human gates (merge approval, confirmation on destructive actions, and worker dry-run), and guidance that states intended use. | Allow-list, approval record, dry-run grant |
| A.10 Third-party relationships | Provider credentials, the MCP gateway (an organization-held credential, tool permissions, rate limits, and audit), and per-key model allow-lists. | MCP permission, audit row |
The security-review pack covers objectives beyond this crosswalk. Request it from security@corveil.com, the same path at the bottom of the Trust Center.