Seatext library / BotRefund evidence

How to Access SeaText AI's ISO Certificates: A Practical Guide

SeaText AI holds ISO 27001, ISO 27017, and ISO 27018 certifications. The actual certificate documents are not published directly on their public website; you need to request them from SeaText's sales or compliance team....

Built for advertisers who need clear, refund-ready traffic evidence.

SeaText AI maintains three active ISO certifications: ISO 27001 for information security management, ISO 27017 for cloud security controls, and ISO 27018 for protecting personally identifiable information in public cloud environments. The certificate PDFs themselves are not posted on the public marketing site. To review them, contact SeaText's sales or compliance team directly and ask for the current certificate copies; they typically provide them after a basic verification step or under a mutual NDA.

What ISO certificates SeaText AI currently holds

According to SeaText's own security and compliance page, the company is "fully certified" for three standards:

  • ISO 27001 — the baseline information security management system (ISMS) standard. It covers risk assessment, policy framework, asset management, access control, incident management, and continuous improvement.
  • ISO 27017 — a cloud-specific extension that adds controls for virtual server infrastructure, shared responsibility, and cloud service provider relationships.
  • ISO 27018 — a privacy-focused extension that defines controls for processing personally identifiable information (PII) in public cloud environments.

These three certifications together signal that SeaText has built a management system that addresses general security, cloud-specific risks, and data privacy obligations — a common stack for B2B SaaS vendors targeting enterprise customers.

Why ISO certifications matter for an AI website optimization platform

SeaText's AI modifies website content in real time for each visitor: translating, rewriting, and adjusting layout. That means the service sits in the critical rendering path, processes visitor data, and often integrates with analytics and advertising pixels. An ISO 27001-based ISMS gives you evidence that the vendor has:

  • Documented risk treatment plans for data leakage, unauthorized modification, and service disruption.
  • Defined roles for security ownership, not just ad-hoc engineering fixes.
  • Regular internal audits and management reviews — not a one-time checkbox.
  • Supplier management controls, which matter because SeaText likely uses cloud infrastructure (AWS, GCP, Azure) and third-party AI models.

ISO 27017 and 27018 extend that baseline to the cloud layer and to PII handling — both relevant when a script runs on your domain and sees visitor IPs, referrers, and behavior signals.

How to request the actual certificate documents

  1. Identify the right contact. Start with your SeaText account manager or the general sales email. If you're in a procurement or vendor-risk process, ask for the "compliance" or "security" contact.
  2. State the purpose. Mention whether you need the certificates for a vendor risk assessment, SOC 2 mapping, cyber insurance, or a client audit. This helps them route the request to the right person.
  3. Expect a verification step. Most vendors confirm you're a current customer, a serious prospect, or an authorized auditor before sending certificate PDFs. Some use a trust portal (e.g., Drata, Vanta, OneTrust) where you can self-serve after signing an NDA.
  4. Check certificate details. When you receive the PDFs, verify: the certification body (accredited registrar), the certificate number, the scope statement (does it cover the SeaText AI service you use?), the issue and expiry dates, and the surveillance audit schedule.
  5. Request the Statement of Applicability (SoA) if needed. The SoA lists which Annex A controls are in scope, excluded, or justified. It's more detailed than the certificate itself and often required for thorough vendor reviews.

What to look for in an ISO certificate

ElementWhy it mattersWhat to verify
Certification bodyMust be an accredited registrar (e.g., ANAB, UKAS, DAkkS)Check the logo and accreditation mark on the certificate
Scope statementDefines exactly which products, locations, and processes are coveredEnsure "SeaText AI website optimization service" or similar is explicitly listed
Certificate numberUnique identifier for validationCan be cross-checked with the registrar's public directory
Issue / expiry datesCertificates are valid for three years with annual surveillance auditsConfirm the certificate is current and surveillance audits are up to date
Standard versionISO 27001:2022 is the current version; older 2013 certificates are in transitionLook for "ISO/IEC 27001:2022" on the document

Differences between ISO 27001, 27017, and 27018

Think of them as layers:

  • ISO 27001 is the foundation — the ISMS framework, risk process, and 93 controls in Annex A (2022 version).
  • ISO 27017 adds 7 cloud-specific controls and implementation guidance for both cloud customers and providers. It clarifies shared responsibility: who patches the hypervisor, who configures the firewall, who encrypts data at rest.
  • ISO 27018 adds 8 privacy controls for PII processors in public cloud. It covers consent, data minimization, breach notification to cloud customers, and restrictions on using PII for advertising.

SeaText holding all three suggests they've addressed the full stack: governance, cloud infrastructure, and privacy. But the certificate scope line is what tells you whether your specific use case (e.g., EU visitor data processed on US infrastructure) is actually covered.

Limitations: what an ISO certificate does not guarantee

  • No product security guarantee. ISO certifies the management system, not the code. A certified vendor can still ship vulnerabilities.
  • Scope can be narrow. Some companies certify only a subset of services or a single data center. Always read the scope line.
  • Point-in-time snapshot. The certificate reflects the last audit. Changes between audits (new features, new sub-processors) may not be reflected until the next surveillance.
  • No substitute for your own testing. You still need penetration tests, dependency scanning, and contractual security clauses (DPAs, SLAs, right-to-audit).
  • Not a privacy law certification. ISO 27018 helps with GDPR accountability but is not a GDPR certification. You still need a DPA and lawful basis analysis.

Key facts from SeaText's public statements

FactDetailSource
ISO 27001 statusFully certified information security management systemS1
ISO 27017 statusFully certified cloud security controls for virtual server infrastructureS1
ISO 27018 statusFully certified practices for protecting PII in public cloud computing environmentsS1
Certificate availabilityNot published on public website; request via sales/compliance contactInferred from standard SaaS practice
LeadershipSergei Gluhov (CEO), 20-year CRO/tech background; Yessi Montoya (CTO)S1
Core serviceAI that dynamically adapts website experience per visitor: translation, copy optimization, mobile concisionS1

Frequently asked follow-up questions

Can I get the certificates without being a customer?

Usually not. Most vendors require at least a signed NDA or a verified procurement request. If you're evaluating SeaText, ask your sales rep to include certificate access in the evaluation package.

Are the certificates for SeaText AI or for BotRefund?

The source page (botrefund.com/about-us) lists the certifications under "Security & Compliance" alongside SeaText AI branding and leadership. BotRefund appears to be a product within the SeaText suite. Confirm with the vendor whether the certificate scope covers both the core SeaText AI service and the BotRefund module.

What if the certificate expires during my contract?

ISO certificates are valid for three years with annual surveillance audits. Ask for the surveillance audit reports or at least confirmation that audits are current. Include a clause in your MSA requiring the vendor to maintain certification and notify you of any lapse.

Does ISO 27018 mean SeaText is GDPR compliant?

ISO 27018 is a control set for PII processors in cloud environments. It supports GDPR Article 28 (processor obligations) and accountability, but it is not a GDPR certification. You still need a Data Processing Addendum, lawful basis for each processing purpose, and possibly Standard Contractual Clauses for international transfers.

Can I audit SeaText myself?

ISO 27001 includes a right-to-audit control (A.15.2.1 in 2013, A.5.28 in 2022). Whether SeaText honors customer audits depends on your contract. Enterprise agreements often include an annual audit right with reasonable notice and scope limitations.

What other security documentation should I request?

Beyond the ISO certificates, ask for: the latest penetration test summary (redacted), SOC 2 Type II report if available, sub-processor list, incident response plan summary, and business continuity/disaster recovery test results.

Next steps for your vendor review

  1. Email your SeaText contact (or sales@seatext.com) with: "Please provide current ISO 27001, 27017, and 27018 certificates and the Statement of Applicability for our vendor risk assessment."
  2. When you receive the PDFs, verify the five certificate elements in the table above.
  3. Map the certificate scope to your actual use case: which domains, which visitor data, which regions.
  4. Request the sub-processor list and confirm cloud provider certifications (AWS, GCP, Azure all hold their own ISO 27001/27017/27018).
  5. Document the review in your vendor risk register with the certificate expiry date as a renewal trigger.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more