Isolio has completed its Cyber Essentials certification. The scheme is backed by the UK government and sets a clear baseline for how organisations protect themselves, and their customers, against the most common internet-borne threats.
For a company that designs, builds and deploys white-label AI agents inside other people's software, that baseline is not a badge of convenience. It is part of how we earn the right to sit inside a customer's product, on their infrastructure, with their data.
Why this certification matters for embedded AI
Enterprise buyers already ask how agents are hosted, who can see customer records and whether any of that data trains a third-party model. Those questions sit alongside the usual security questionnaires. Cyber Essentials does not replace a SOC 2 report or an ISO 27001 programme. It does prove that Isolio has implemented the five technical controls the scheme requires: secure configuration, access control, malware protection, security update management and firewalls at the boundary.
That is the same discipline we apply when we deploy agents under a customer's brand. Access follows their permissions. Data stays inside their estate. Nothing is used as someone else's training set.
What customers should take from this
SaaS platforms that embed Isolio agents are asking their customers to trust a new kind of capability: software that can read records, take actions and operate with limited supervision. Trust of that kind is earned in layers. Product quality is one. Governance is another. Independent confirmation that our own house is in order is a third.
Cyber Essentials is that third layer. It is independently assessed. It is recognised by UK public-sector and regulated buyers. And it sits alongside Isolio's existing commitments: UK-registered, privacy-first, deployed on your infrastructure with your keys and your audit trail.
What does not change
Certification is not a destination. The controls we evidenced for Cyber Essentials are the same controls we operate every day: least-privilege access, current patching, monitored boundaries and a clear split between Isolio's environment and the customer environments we deploy into.
If you are mapping AI into a product that already has to survive security reviews, this is the standard we hold ourselves to before we ask you to hold us inside yours.
If you want to talk through how that maps to your own questionnaires, book a fit call.

