π Askable is ISO 42001 certified - here's what that means for you
Askable has achieved ISO/IEC 42001:2023 certification - the world's first international standard for AI management systems. We're one of a small number of SaaS platforms globally to hold this certification, and we're proud of it.
β
ISO 42001 means an independent auditor has verified that our AI isn't just built to be useful - it's built to be responsible, transparent, and accountable. It covers how we govern AI across our entire platform: how we assess risk, how we design safeguards, how we document decisions, and how we make sure AI supports people rather than replaces their judgement.
β
For you, this means: when you use Askable AI, you're working with a platform that has been externally verified against the highest international standard for AI governance. Not just a policy statement - a certification.
β
π View our full certification status at trust.askable.com
This overview explains what Askable AI does, when and why it's used, and the security and privacy safeguards behind it - so you know exactly how your data is handled and protected.
What is Askable AI?
Askable AI is the intelligence layer across our entire research platform - not bolted-on chatbots, but purpose-built AI for research workflows. It powers three core capabilities:
Platform AI | AI Moderation | AI Repository |
AI to help you work more efficiently - set up studies with AI, automated transcription, and intelligent workflow automation. | Real-time AI interviews in 15+ native languages that ask contextual follow-up questions. | Natural-language Q&A that returns answers linked to source transcripts. Your institutional memory that connects insights across all studies - plus thematic analysis. |
Askable leverages technology from several approved AI subprocessors, which we publish here: trust.askable.com/subprocessors
How does Askable AI work?
Who are Askableβs Large Language Model Providers?
We leverage pre-trained LLMs from leading AI organisations:
Anthropic - Advanced reasoning tasks and complex analysis
OpenAI - LLM capabilities, text-to-speech, and speech-to-text
AWS Bedrock - LLM capabilities and embeddings
Askable is model-agnostic. We continuously evaluate providers and switch if better options emerge. You're never locked into underperforming tech.
Important: These models follow their providers' safety practices (Anthropic's and OpenAI's established frameworks). Our AI tools are designed to support researchers - not make automated decisions about individuals.
All AI Subprocessors
View our complete, up-to-date subprocessor list at: trust.askable.com/subprocessors
β
You can subscribe to notifications when we add new subprocessors at the same link. Askable publishes all planned subprocessor changes at trust.askable.com, and we notify all affected customers by email before any new subprocessor is authorised to process personal data.
How is my data protected?
Can other companies see our research data and insights?
No. Logical separation using team and user IDs ensures strict boundaries between customer accounts. We do not mix or process data from different customers together during AI processing. Your data is never exposed to other Askable customers.
How is Customer Data protected when sent to AI Subprocessors?
Askable AI is designed to protect your Customer Data and prevent information leaks to other users of the service.
β
Prior to engaging any third-party subprocessor, Askable evaluates their privacy, security, and confidentiality practices, and executes agreements implementing applicable security, privacy, and legal obligations.
β
All subprocessors are monitored and reviewed at least annually to ensure continued compliance. This includes reviewing attestation reports, penetration tests, and other artefacts based on the subprocessor's criticality.
β
When we send your data to third parties, it is encrypted in transit using TLS 1.2 or greater.
β
For more information about how Askable processes your data, please refer to our Data Processing Addendum.
Will my data be used to train any models?
No. Askable and its AI subprocessors do not use Customer Data to train any models. We have contractual agreements in place with our AI subprocessors that explicitly prohibit this.
β
Your use of Askable AI does not grant Askable any right or licence to your Customer Data to train machine learning models.
How is Customer Data segregated?
Logical separation: All AI tools are initialised with the user's access and permissions, enforcing all existing Askable security controls. This means the AI only has access to the data of the user who initiated the request - it cannot bypass customer boundaries.
β
Workspace permissions respected: AI only accesses content you have permission to see. No backdoor access.
What are the data retention obligations of third-party AI providers?
When using Askable AI, our LLM providers utilise zero data retention. Data is only held in third-party servers for the duration of processing, and for a short period post-processing for caching and monitoring purposes.
What compliance standards does Askable AI meet?
Askable AI is included in the scope of all of our active certifications and compliance frameworks:
Standard | Scope | Status |
SOC 2 Type II | Security, availability, and confidentiality controls | β Certified - audited annually |
ISO/IEC 27001:2022 | Information security management | β Certified |
ISO/IEC 27701:2019 | Privacy information management | β Certified |
ISO/IEC 42001:2023 | AI management system | β Certified |
GDPR | European data protection standards | β Compliant |
Cyber Essentials | UK government-backed cyber security baseline | β Certified |
What this means: Our AI isn't just governed by policy statements - it's audited by independent external organisations against international standards. ISO 42001 in particular means our entire AI governance programme - from risk assessment to design decisions to accountability structures - has been verified by a third party.
What controls exist or can be added?
AI features included in the AI Moderation or AI Repository products cannot be opted out of, as these are both AI-native features. If you'd like to opt out of Platform AI features, you can request this through customer support.
