Skip to content
Assessment certification

Proof of an independent assessment — not a badge you can buy

Every Safe Tech AI security assessment can end in a certificate: a public, verifiable record of what was assessed, against which parameters, and when. It names the organisation, the assessment type, and the validity window, and anyone can check it is genuine in seconds.

What the mark is

  • An attestation that the named organisation's stated scope was independently assessed against a published, versioned parameter checklist.
  • Time-bound: valid for a stated period, and only for the scope described — not a permanent or open-ended claim.
  • Verifiable at any time via its QR code, or its certificate number and issue date, so a reader never has to take the document on faith.

What the mark is not

  • Safe Tech AI is not an accredited certification body. This document is an independent security assessment attestation, not an accredited certification.
  • It is not a substitute for ISO 27001 certification, SOC 2, or any regulatory audit — those follow their own accredited processes.
  • It does not publish vulnerability counts or findings detail, and it never certifies a system is unconditionally "secure" — only that it was assessed against the stated parameters at a point in time.
Assessment types

Four assessment types, each with its own checklist

Every certificate snapshots the exact parameters ticked at issue, using the wording in force at that time — the checklists below are how those parameters read today.

API Security Testing

Assessment of REST, GraphQL, or internal APIs against authentication, authorisation, injection, abuse, and transport-security risks, performed against a defined set of endpoints. Testing covers how each endpoint verifies identity, enforces access, handles untrusted input, and behaves under automated abuse, so the checklist reflects what a thorough API assessment actually examines rather than a generic scan.

  • Authentication and authorisation controls

    Whether endpoints correctly establish who the caller is and what they may access, including object-level and function-level authorisation checks.

  • Injection and input validation

    Whether untrusted input is validated and safely handled, covering SQL, NoSQL, command, and template injection classes.

  • Rate limiting and abuse controls

    Whether endpoints resist automated abuse, credential stuffing, and resource-exhaustion patterns.

  • Business-logic abuse cases

    Whether workflows can be driven into unintended states by valid-looking requests in an unexpected order or quantity.

  • Transport security configuration

    Whether traffic is protected in transit with current TLS configuration and no downgrade paths.

  • Error handling and information exposure

    Whether error responses avoid leaking stack traces, internal hostnames, credentials, or user data.

Web Application VAPT

OWASP-aligned vulnerability assessment and penetration testing of a web application, covering access control, authentication, injection, configuration, and client-side risk classes. Automated scanning is combined with hands-on manual testing across the application's real workflows, checking how it enforces permissions, handles sessions, and manages the components and dependencies it depends on.

  • Access control and privilege separation

    Whether users can reach data or actions outside their role, horizontally or vertically.

  • Authentication and session management

    Whether login, session lifetime, logout, and credential-recovery flows resist takeover.

  • Injection and unsafe data handling

    Whether untrusted input reaches interpreters — SQL, command, or template — without safe handling.

  • Security misconfiguration

    Whether servers, frameworks, headers, and default credentials are hardened for production.

  • Cross-site scripting and client-side risk

    Whether attacker-controlled content can execute in another user's browser session.

  • Vulnerable and outdated components

    Whether dependencies with known exploitable vulnerabilities are in use.

Cloud Security Assessment

Review of a cloud environment's identity, network, data-protection, logging, and resilience configuration against a defined baseline for the accounts and services in scope. The assessment examines who can access what, how workloads are exposed to the internet, whether stored data is encrypted, and whether activity is logged well enough to detect and recover from an incident.

  • Identity and access management

    Whether identities, roles, and permission boundaries follow least privilege, including key and MFA hygiene.

  • Network exposure and segmentation

    Whether workloads are isolated appropriately and no service is unintentionally reachable from the internet.

  • Data protection and encryption at rest

    Whether stored data is encrypted with managed keys and access to those keys is controlled.

  • Logging, monitoring, and alerting

    Whether control-plane and data-plane activity is logged, retained, and alerted on.

  • Backup and disaster recovery readiness

    Whether backups exist, are protected from deletion, and have a tested restore path.

  • Configuration baseline and drift

    Whether resources match a hardened baseline and drift from it is detected.

Network and Infrastructure VAPT

Vulnerability assessment and penetration testing of network infrastructure, covering external and internal attack surface, patching, segmentation, service hardening, and egress control. Testing looks at what is reachable from outside, how far an attacker could move after gaining a foothold inside, and whether devices, credentials, and outbound traffic are configured to resist common attack techniques.

  • External attack surface

    Which services are reachable from the internet and whether any should not be.

  • Internal attack surface and lateral movement

    How far an attacker with a foothold could move within the network.

  • Patch and vulnerability management

    Whether hosts and network devices carry known exploitable vulnerabilities.

  • Network segmentation and egress filtering

    Whether sensitive zones are separated from general-purpose networks in practice, and outbound traffic is restricted enough to impede exfiltration and command-and-control.

  • Service and device hardening

    Whether exposed services run with hardened, non-default configuration.

  • Credential hygiene

    Whether default, shared, or weak credentials are present on infrastructure.

Verification

Anyone can verify a certificate in seconds

  1. 1

    Every certificate carries a certificate number (e.g. STA-API-2026-0042) and a QR code.

  2. 2

    Scanning the QR code, or entering the number and issue date at safetechai.com/verify, opens the certificate's Safe Tech AI verification page.

  3. 3

    The page shows the certificate's current status — verified, expired, or revoked — so an outdated or revoked certificate can never be passed off as current.

Get an assessment that ends in a certificate

Start with a free manual assessment. If a certificate makes sense for your scope, it's part of the engagement, not an upsell.