Every action controlled. Every decision explainable. Every write reversible.
HachiAI's Intelligent Digital Workers run under enterprise-grade governance, built in from day one, not bolted on after. Every action goes through scoped access and policy checks, high-risk writes wait for a human approval, every step lands in an immutable audit trail, and any write rolls back in one click. Deployed wherever your compliance requires: our cloud, your private cloud, hybrid, or on-prem.
ISO 27001 & ISO 42001 certified · GDPR & PIPEDA compliant · SOX, HIPAA, and SOC 2 Type II deployment paths on request.
100%Actions audit-trailed
HITLOn high-impact writes
1-clickRollback with full trail
4Deployment models
What do these certifications actually prove?
Three external standards back the controls above. ISO 27001 and ISO 42001 are verified by accredited third-party auditors, not self-declared. Here is what each one covers, and why it matters for you.
ISO/IEC 27001
Information security, certified
The international standard for information security management. An accredited, independent auditor verifies that we have the controls, processes, and continual monitoring needed to protect the confidentiality, integrity, and availability of your data.
For you: your operational data is protected by audited security controls, not just our assurances.
ISO/IEC 42001:2023 is the first international standard for AI management systems. It defines how an organization governs the AI it builds and operates: risk management, transparency, human oversight, bias and data quality, and continual improvement. It is new and demanding, and few AI vendors hold it yet.
For you: proof our AI is run under an audited governance framework, not deployed ad hoc, the assurance a board and risk team need before AI touches production.
GDPR
Data privacy, compliant
The EU General Data Protection Regulation governs how personal data is collected, processed, and stored. We handle data lawfully and transparently, with data minimization, purpose limitation, and respect for individuals' rights, including access and erasure.
For you: personal and customer data in your workflows is handled to a recognized global privacy bar, and is never used to train public models.
Controlled, explainable, reversible by design.
Controlled · Every action
IDWs act only through pre-approved tools and scoped credentials, with policy and risk checks on every step.
Score
Explainable · Every decision
Each decision carries its reasoning and a confidence score, so you can see why an action was taken, not just that it was.
Reversible · Every write
High-impact writes pass through human approval, and any action can be rolled back in one click with a full audit trail.
Enterprise-grade governance, built in from day one.
Only pre-approved tools can execute writes, each with least-privilege, scoped access.
Run it wherever your compliance requires.
From fully managed cloud to fully local, the same governance applies in every model.
Cloud
Same governance
Scoped access
Audit trail
Private Cloud
Same governance
Scoped access
Audit trail
Hybrid
Same governance
Scoped access
Audit trail
On-premises
Same governance
Scoped access
Audit trail
Your data stays private and secure.
Security controls · Enterprise-compliant by design.
Identity management and access control
Data governance and model isolation
Encrypted credentials at rest and in transit
Local model support for sensitive processing
SOX, HIPAA, and SOC 2 Type II deployment paths available on request
Data security & privacy · Your operational data stays yours.
Sensitive data stored locally in self-hosted deployments
Task artifacts remain within designated local directories
Credentials encrypted at rest, used only for approved actions
Your data is never used to train public models
Your environment
Encrypted
Local model support
Your dataNever trains public models
Certified and compliant to the frameworks your auditors expect.
Independently certified, with deployment paths for the frameworks your auditors expect.
ISO 27001 Certified
ISO 42001 Certified
GDPR & PIPEDA Compliant
SOX path
HIPAA path
SOC 2 Type II path
Governance questions leaders ask us.
How is the work governed?
IDWs never operate unchecked: scoped credentials, policy-based approval thresholds, human review on high-risk writes, immutable before-and-after audit trails, low-confidence escalation, and rollback where an action is reversible, with defined remediation and escalation where it is not. Every action is controlled and reviewable.
Is our data secure? Can it run on-premise?
Yes. Your data stays private and is never used to train public models. HachiAI is ISO 27001 and ISO 42001 certified and GDPR and PIPEDA compliant, and IDWs deploy in our cloud, your private cloud, or fully on-premise for regulated environments.
Governance you can take to your board.
See exactly how these controls apply to your workflows, systems, and compliance requirements. Built and run by operators who have carried this work through audits in production.