Proof of an independent assessment — not a badge you can buy
Every Safe Tech AI security assessment can end in a certificate: a public, verifiable record of what was assessed, against which parameters, and when. It names the organisation, the assessment type, and the validity window, and anyone can check it is genuine in seconds.
What the mark is
- An attestation that the named organisation's stated scope was independently assessed against a published, versioned parameter checklist.
- Time-bound: valid for a stated period, and only for the scope described — not a permanent or open-ended claim.
- Verifiable at any time via its QR code, or its certificate number and issue date, so a reader never has to take the document on faith.
What the mark is not
- Safe Tech AI is not an accredited certification body. This document is an independent security assessment attestation, not an accredited certification.
- It is not a substitute for ISO 27001 certification, SOC 2, or any regulatory audit — those follow their own accredited processes.
- It does not publish vulnerability counts or findings detail, and it never certifies a system is unconditionally "secure" — only that it was assessed against the stated parameters at a point in time.
Four assessment types, each with its own checklist
Every certificate snapshots the exact parameters ticked at issue, using the wording in force at that time — the checklists below are how those parameters read today.
API Security Testing
Assessment of REST, GraphQL, or internal APIs against authentication, authorisation, injection, abuse, and transport-security risks, performed against a defined set of endpoints. Testing covers how each endpoint verifies identity, enforces access, handles untrusted input, and behaves under automated abuse, so the checklist reflects what a thorough API assessment actually examines rather than a generic scan.
Authentication and authorisation controls
Whether endpoints correctly establish who the caller is and what they may access, including object-level and function-level authorisation checks.
Injection and input validation
Whether untrusted input is validated and safely handled, covering SQL, NoSQL, command, and template injection classes.
Rate limiting and abuse controls
Whether endpoints resist automated abuse, credential stuffing, and resource-exhaustion patterns.
Business-logic abuse cases
Whether workflows can be driven into unintended states by valid-looking requests in an unexpected order or quantity.
Transport security configuration
Whether traffic is protected in transit with current TLS configuration and no downgrade paths.
Error handling and information exposure
Whether error responses avoid leaking stack traces, internal hostnames, credentials, or user data.
Web Application VAPT
OWASP-aligned vulnerability assessment and penetration testing of a web application, covering access control, authentication, injection, configuration, and client-side risk classes. Automated scanning is combined with hands-on manual testing across the application's real workflows, checking how it enforces permissions, handles sessions, and manages the components and dependencies it depends on.
Access control and privilege separation
Whether users can reach data or actions outside their role, horizontally or vertically.
Authentication and session management
Whether login, session lifetime, logout, and credential-recovery flows resist takeover.
Injection and unsafe data handling
Whether untrusted input reaches interpreters — SQL, command, or template — without safe handling.
Security misconfiguration
Whether servers, frameworks, headers, and default credentials are hardened for production.
Cross-site scripting and client-side risk
Whether attacker-controlled content can execute in another user's browser session.
Vulnerable and outdated components
Whether dependencies with known exploitable vulnerabilities are in use.
Cloud Security Assessment
Review of a cloud environment's identity, network, data-protection, logging, and resilience configuration against a defined baseline for the accounts and services in scope. The assessment examines who can access what, how workloads are exposed to the internet, whether stored data is encrypted, and whether activity is logged well enough to detect and recover from an incident.
Identity and access management
Whether identities, roles, and permission boundaries follow least privilege, including key and MFA hygiene.
Network exposure and segmentation
Whether workloads are isolated appropriately and no service is unintentionally reachable from the internet.
Data protection and encryption at rest
Whether stored data is encrypted with managed keys and access to those keys is controlled.
Logging, monitoring, and alerting
Whether control-plane and data-plane activity is logged, retained, and alerted on.
Backup and disaster recovery readiness
Whether backups exist, are protected from deletion, and have a tested restore path.
Configuration baseline and drift
Whether resources match a hardened baseline and drift from it is detected.
Network and Infrastructure VAPT
Vulnerability assessment and penetration testing of network infrastructure, covering external and internal attack surface, patching, segmentation, service hardening, and egress control. Testing looks at what is reachable from outside, how far an attacker could move after gaining a foothold inside, and whether devices, credentials, and outbound traffic are configured to resist common attack techniques.
External attack surface
Which services are reachable from the internet and whether any should not be.
Internal attack surface and lateral movement
How far an attacker with a foothold could move within the network.
Patch and vulnerability management
Whether hosts and network devices carry known exploitable vulnerabilities.
Network segmentation and egress filtering
Whether sensitive zones are separated from general-purpose networks in practice, and outbound traffic is restricted enough to impede exfiltration and command-and-control.
Service and device hardening
Whether exposed services run with hardened, non-default configuration.
Credential hygiene
Whether default, shared, or weak credentials are present on infrastructure.
Anyone can verify a certificate in seconds
- 1
Every certificate carries a certificate number (e.g. STA-API-2026-0042) and a QR code.
- 2
Scanning the QR code, or entering the number and issue date at safetechai.com/verify, opens the certificate's Safe Tech AI verification page.
- 3
The page shows the certificate's current status — verified, expired, or revoked — so an outdated or revoked certificate can never be passed off as current.
Get an assessment that ends in a certificate
Start with a free manual assessment. If a certificate makes sense for your scope, it's part of the engagement, not an upsell.