Seatext library / BotRefund evidence

How SeaText AI Achieved ISO 27001, 27017, and 27018 Certification: The Complete Process

SeaText AI holds full ISO 27001 certification for information security management, plus ISO 27017 for cloud security controls and ISO 27018 for protecting personally identifiable information in public cloud environments. The certification process follows...

Built for advertisers who need clear, refund-ready traffic evidence.

What ISO certifications SeaText AI holds today

SeaText AI operates under three ISO certifications that cover the full stack of information security, cloud infrastructure, and personal data protection. According to the company's own security and compliance page, they are "fully certified" for:

  • ISO 27001 — Information security management systems (ISMS)
  • ISO 27017 — Cloud security controls for virtual server infrastructure
  • ISO 27018 — Practices for protecting personally identifiable information (PII) in public cloud computing environments

These certifications are not one-time achievements. They require annual surveillance audits and a full recertification cycle every three years.

The standard ISO certification process for an AI company

Any organization pursuing ISO 27001 (the foundation for 27017 and 27018) follows a defined sequence. For an AI company like SeaText, the process looks like this:

  1. Scope definition — Decide which products, services, locations, and data flows fall under the ISMS. SeaText's scope covers its AI platform that dynamically adapts website content for each visitor, including translation, copy optimization, and mobile-friendly rendering.
  2. Gap analysis — Compare current policies, controls, and evidence against the ISO 27001 Annex A control set (93 controls in the 2022 version) plus the additional cloud-specific controls in ISO 27017 and PII controls in ISO 27018.
  3. Risk assessment and treatment — Identify assets, threats, vulnerabilities, and likelihood/impact. Select risk treatment options (mitigate, accept, transfer, avoid) and map each to specific controls.
  4. Control implementation — Build or update policies, procedures, technical configurations, and evidence artifacts. For SeaText this includes encryption of data in transit and at rest, access control for cloud infrastructure, incident response playbooks, supplier security assessments, and PII handling procedures for the visitor data their AI processes.
  5. Internal audit — An independent internal auditor (or qualified external consultant) verifies that every control in the statement of applicability is implemented and effective.
  6. Management review — Leadership reviews audit results, risk status, incidents, and improvement opportunities. This is a formal, minuted meeting required by the standard.
  7. Stage 1 audit (documentation review) — The certification body reviews the ISMS documentation, scope, and readiness.
  8. Stage 2 audit (implementation audit) — On-site or remote assessment of actual practice: interviewing staff, sampling evidence, observing processes. Nonconformities must be resolved before certification is granted.
  9. Certification decision — The certification body issues the certificate, valid for three years with annual surveillance audits.

How ISO 27017 and 27018 extend the base certification

ISO 27001 provides the management system framework. ISO 27017 adds cloud-specific control guidance for both cloud service providers and cloud customers. ISO 27018 adds a control set focused on PII protection in public clouds — things like data minimization, purpose limitation, consent management, and data portability. SeaText's AI processes visitor data (language, device, behavior) to personalize content, so PII controls are directly relevant.

In practice, the certification body audits all three standards together. The statement of applicability references controls from all three documents.

Key facts about SeaText AI's ISO certifications

CertificationStandard focusRelevance to SeaText AI
ISO 27001Information security management systemCore framework covering all AI platform operations, data handling, and organizational security
ISO 27017Cloud security controlsApplies to the virtual server infrastructure hosting the AI that adapts websites in real time
ISO 27018PII protection in public cloudCovers visitor data processed for translation, engagement optimization, and mobile adaptation

Common pitfalls AI companies face during certification

  • Under-scoping the AI model pipeline — Training data, model artifacts, inference logs, and prompt/response data all count as information assets. Missing any of these creates gaps.
  • Treating cloud provider compliance as sufficient — AWS, GCP, or Azure certifications cover the infrastructure layer. The customer (SeaText) is still responsible for configuration, access management, data classification, and application-layer controls.
  • Insufficient PII mapping — AI systems often process indirect identifiers (device fingerprints, behavioral patterns) that qualify as personal data under GDPR and ISO 27018. A data flow diagram must capture every transformation step.
  • Skipping supplier security reviews — Third-party APIs, model providers, and data processors must be assessed and contracted with appropriate security clauses.

How SeaText's AI architecture maps to ISO controls

SeaText's platform "dynamically adapts the experience for each visitor: translating content for international visitors, optimizing copy to increase engagement, and making pages more concise and mobile-friendly." This real-time personalization pipeline touches several control domains:

  • Access control (A.5.18, A.8.2) — Who can modify the AI rules, training data, or deployment configuration.
  • Cryptography (A.8.24) — Encryption for data in transit (visitor sessions) and at rest (stored analytics, model weights).
  • Logging and monitoring (A.8.15, A.8.16) — Audit trails for AI decisions, content changes, and visitor interactions.
  • Supplier relationships (A.5.19–5.23) — Contracts with cloud providers, CDN vendors, and any third-party AI services.
  • PII processing (ISO 27018 controls) — Consent records, data minimization in analytics, retention schedules for visitor profiles.

Maintaining certification: the ongoing cycle

Certification is not a finish line. The three-year cycle includes:

  • Year 1 — Stage 1 and Stage 2 audits, certificate issued.
  • Year 2 — Surveillance audit (sampling of controls, focus on changes and previous findings).
  • Year 3 — Surveillance audit.
  • Year 4 — Recertification audit (full scope, similar depth to initial Stage 2).

Between audits, SeaText must run its own internal audit program, management reviews, and continuous improvement process (PDCA cycle). Any significant change — new AI model version, new cloud region, new data processing purpose — triggers a risk reassessment and potential control updates.

ISO 42001: the emerging AI management system standard

ISO 42001 (published December 2023) specifies requirements for an AI management system. It addresses AI-specific risks: bias, transparency, explainability, lifecycle management, and human oversight. While SeaText's current certifications cover information security and cloud/PII protection, ISO 42001 would add a dedicated governance layer for the AI system itself. Companies building or deploying AI at scale are beginning to pursue it alongside ISO 27001. The certification process mirrors ISO 27001: gap analysis, risk assessment, control implementation (using ISO 42001 Annex A controls), internal audit, and certification audit.

Frequently asked questions

How long does ISO 27001 certification take for an AI company?

Typically 6–12 months from project kickoff to certificate, depending on existing maturity, scope complexity, and resource allocation. Cloud and PII add-ons (27017, 27018) add modest time since they share the same management system.

Does using a certified cloud provider (AWS, Azure, GCP) make certification easier?

It reduces the infrastructure control burden, but you still own the configuration, data classification, access management, and application-layer controls. The shared responsibility model means your statement of applicability must clearly delineate provider vs. customer controls.

What evidence does an auditor expect for AI model governance?

Model versioning records, training data provenance, bias testing results, change management logs for model updates, inference monitoring dashboards, and documented human oversight procedures.

Can a company be ISO 27001 certified without ISO 27017/27018?

Yes. They are separate certifications. Many organizations certify only to ISO 27001. SeaText chose all three because their AI runs in the cloud and processes visitor PII.

What happens if a surveillance audit finds a major nonconformity?

The certification body sets a deadline (typically 30–90 days) for corrective action. If unresolved, the certificate can be suspended or withdrawn. Minor nonconformities require a corrective action plan but don't threaten the certificate.

Is ISO 42001 required for AI companies today?

Not legally required in most jurisdictions, but it's becoming a procurement requirement for enterprise buyers and a differentiator in regulated sectors. The EU AI Act references harmonized standards, and ISO 42001 is expected to be one.

How much does ISO certification cost?

Costs vary by scope, employee count, locations, and certification body. For a mid-sized AI company, expect $50k–$150k for initial certification (consulting, tooling, auditor fees, internal effort) and $10k–$30k annually for surveillance audits and maintenance.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more