Security Assured / Products / Assured-1
Assured-1 is independent certification for organizations deploying AI — proof, renewed continuously, that it stays inside the boundaries it was built to respect.
Every quarter, AI systems take on more autonomy — approving transactions, drafting decisions, touching regulated data — inside businesses that have never had to prove control at this speed before. Assured-1 is built for that trajectory, not just this year's checklist.
This is the scale Assured-1 is built for — today, and at whatever scale AI reaches next.
Assured-1 doesn't rank these — certification requires all three, running together, at once.
Data protection, operational boundaries, and permission scoping enforced around every deployed agent — not just documented in a policy.
Active adversarial testing of AI agents under real attack conditions, on a standing cadence rather than a one-time exercise.
Continuous decision logging and an unbroken audit trail, so every action an agent takes can be traced, explained, and defended.
Assured-1 doesn't require a specific stack, and it never will. Assessors evaluate what an organization's own tools can prove — whatever those tools happen to be.
An assessor reviews the logs, controls, and test results a system actually produces — not the logo on the dashboard that produced them.
Whether it's a single API call or a full agentic pipeline stitched across a dozen providers, the same three pillars apply the same way.
Tooling will keep changing faster than any one company can keep up with. A standard that depends on one vendor's product line doesn't survive that — Assured-1 is built to.
A standard finished once and left alone falls behind the thing it was built to govern. Assured-1 is versioned and revised on purpose, so it keeps pace with how AI actually changes.
Controls are reassessed against how AI is actually being built and deployed, not left static until the next headline incident forces a rewrite.
A certification records the exact revision of Assured-1 it was measured against, so anyone checking a badge knows precisely which bar was cleared, and when.
Revisions draw on the assessors, security practitioners, and certified organizations building a track record with the standard — not one company working alone.
A badge that's checked once and never again doesn't say much a year from now. Assured-1 is built to keep being true.
Independent assessor review across all three pillars, with evidence collected on-site or remotely. Valid 12 months, and publicly verifiable.
Start Certification →Ongoing re-verification against the current version of the standard, with drift detection and dual reporting built for both procurement and underwriting audiences.
Add Continuous Monitoring →AI will keep making more decisions, in more places, with less human review at each step. Assured-1 exists so that trajectory comes with a standard attached to it — built in from here forward, not retrofitted after the first incident. Control it. Prove it. Assure it.
No. Assured-1 evaluates the evidence your organization's existing tools can produce across all three pillars — it doesn't require a specific vendor or stack.
Assured-1 assessments are carried out by independent assessors against the published standard — the same evidence-based model used across Security Assured's compliance and assurance work.
Timelines depend on how much evidence is already in place. Most organizations move from scoping to badge issuance within a defined engagement window, not an open-ended process.
Assured-1 is revised on a scheduled cadence as AI capabilities evolve. Every certification is version-locked, so you always know exactly which revision an organization was measured against.
Tier II continuous monitoring keeps checking the same controls year-round, so drift is caught and addressed before the next formal renewal — not discovered at it.